2-day current streak·8-day longest streak
--- 🧠 About Me 🎯 Bug Bounty Hunter on HackerOne & YesWeHack — featured in 18+ Hall of Fames 🛠️ Building open-source security tools for the community 📹 Running B1scuit…











---
🧠 About Me
whoami
> Raunak Gupta a.k.a. B1scuit
> Freelance Security Researcher & Bug Bounty Hunter
> Specializing in: Android • Web • API • Thick-Client Security
> Also into: Open-Source • AI • LLMs
> Location: Rajasthan, India
> Status: Available for hire 🟢
- 🎯 Bug Bounty Hunter on HackerOne & YesWeHack — featured in 18+ Hall of Fames
- 🛠️ Building open-source security tools for the community
- 📹 Running B1scuit Security on YouTube — hacking tutorials & writeups
- ✍️ Writing on Medium — bug bounty tips, resources & POCs
- 🎓 Udemy instructor with 8,400+ learners
- 💬 Running an active Discord community for security researchers
- 🌐 Personal site: b1scuit.pro
🏆 Hall of Fame — Acknowledged By
| Company | Severity | Vulnerability Type |
|:---|:---:|:---|
| 🔵 Supabase | 🔴 High | BAC + Insecure API (rate limiting & input flaws) |
| 🟠 Zerodha | 🔴 High | Android + Business Logic + Security Misconfigurations |
| ⚫ Cert-wm.nl | 🔴 High | Stored XSS via Unrestricted File Upload |
| 🟣 Thinkst Canary | 🟡 Medium | Mass PII Leak |
| 🟢 Substack | 🟡 Medium | Race Condition — Atomic Increment Manipulation |
| 🟢 GeeksForGeeks | 🟡 Medium | Mass Assignment Vulnerability |
| 🔵 Wibmo.com | 🟡 Medium | IDOR — Email Disclosure |
| 🟠 EC-Council | 🟡 Medium | Email Verification Bypass |
| 🟤 Inflectra.com | 🟡 Medium | Open Redirect + PII Leak via Input Validation Flaw |
| 🟣 Skillmate.ai | 🟡 Medium | Security Bypass + Insecure API |
| 🔵 Samsung | 🔵 Low | Misconfigured AWS S3 Bucket — Data Leak |
| ♟️ Chess.com | 🔵 Low | CWE-657: Insecure Design Violation |
| 🟠 Arcjet.com | 🔵 Low | CWE-657: Insecure Design Violation |
| 🏥 CK Birla Hospital | 🔵 Low | Security Bypass + Insecure API |
| 🏥 Sir Ganga Ram Hospital | 🔵 Low | Security Bypass + Insecure API |
| 🏥 Max Healthcare | 🔵 Low | Security Bypass + Insecure API |
| 🟡 Com Olho | 🔵 Low | Security Bypass + Insecure API |
| 🟡 Brandmuscle.com | 🔵 Low | Security Bypass + Insecure API |
> 💰 Also earned a $1,000+ bounty via private YesWeHack program (Android app — Forgot Password flow)
---
🚀 Featured Projects
📚 Learning & Research
| Project | Description | Stars |
|:---|:---|:---:|
| My CyberSecurity Store | Curated collection of infosec tools, resources & references | ⭐ |
| Bug Bounty GitBook | Playbook: tools, methodologies, writeups, labs & checklists | ⭐ |
| Learn Android Bug Bounty | Complete guide to Android application pentesting & bug bounty | ⭐ |
| Learn Beyond Web | Comprehensive guide to Thick-Client security testing | ⭐ |
| Elite Google Dorks Search | Smart Google dorks to surface hidden assets & information | ⭐ |
🤖 Android Security Tools
| Project | Description |
|:---|:---|
| APKDig | Deep APK analysis — extracts security-relevant info |
| analyze_manifest | AndroidManifest.xml analyzer — permissions, deep links, exported components |
| AndroidExportViewer | View & analyze exported Android components |
| DecompileAllAPK-s | Batch APK decompiler with analysis features |
| PullAPKFromPure | Extract APKs directly from Android devices |
🌐 Web Security Tools
| Project | Description |
|:---|:---|
| Bruteforce JWT Secret | Brute-force weak JWT secrets to test auth |
| Elite Burp Suite Analyzer | Advanced HTTP history analyzer with enhanced filtering |
| GitHub Recon Tool | GitHub recon & repo analysis tool |
| Tor IP Changer | Auto-rotate IP via Tor network |
| Single Script Tools | One-script installer for multiple cybersecurity tools |
| CloneAllRepo | Clone all repos from a GitHub user/org |
🔧 Burp Suite Extensions
| Extension | Description |
|:---|:---|
| AutoTabSorter | Auto-organize Burp tabs for workflow efficiency |
| CVSS Calculator | Integrated CVSS scorer inside Burp Suite |
---
📝 Recent Blogs & POCs
- 📄 From JS Recon to HTML Injection — JS recon uncovering HTML injection
- 📄 Hacking Hospital: Mass PII Leak — Healthcare system vulnerability case study
- 📄 The Thousand Dollar Bug — $1000+ bounty writeup via private YesWeHack program
- 📄 30 Must-Read Books to Learn Hacking — Curated reading list
- 📄 55 YouTube Channels to Learn Hacking — Best channels for bug bounty
🛠️ Skills & Stack
!Android
!Burp Suite
!Python
!Frida
!Linux
!API Security
!OWASP
!Git
Target Surfaces: Web Apps • REST/GraphQL APIs • Android Apps • iOS Apps • Thick-Client Apps
Techniques: IDOR • BAC • Race Conditions • Mass Assignment • SQLi • XSS • JWT Attacks • SSL Pinning Bypass • Root Detection Bypass • Business Logic Flaws • AWS Misconfigurations
---
📊 GitHub Stats
---
🎓 Teaching
Udemy Instructor — Security Researcher and Bug Bounty Hunter
- 📌 8,400+ total learners
- 📌 Active courses on cybersecurity, bug bounty & ethical hacking
- 📌 Beginner-friendly content paired with real-world examples
---
💬 Let's Connect
Found a bug in my README? That's... ironic. Hit me up on Discord or Twitter.
⭐ If my tools or resources helped you — drop a star. It keeps the grind going.
-
My-CyberSecurity-Store ★ PINNED
This repository contains a comprehensive collection of learning resources and notes that I've gathered on various topics, including cybersecurity, bug bounty, API security, cloud security, and more. All the resources belong to their respective copyright owners and not to me.
Rust ★ 725 6mo agoExplain → -
Elite-Google-Dorks-Search-by-Biscuit ★ PINNED
Discover hidden information on the web with "Elite Google Dorks Search by Biscuit." This collection offers smart and improved Google search queries to help you find data and vulnerabilities more easily. Perfect for anyone interested in cybersecurity, it makes searching more effective and efficient.
HTML ★ 20 11mo agoExplain → -
Bug-Bounty-GitBook ★ PINNED
Biscuit's Bug Bounty Playbook is a curated hub for cybersecurity learners and bug bounty hunters. It includes tools, methodologies, writeups, vulnerable labs, YouTube channels, checklists, and platform-specific insights to help you build and sharpen your hacking skills. Perfect for beginners and pros alike.
★ 20 2mo agoExplain → -
Learn-android-bug-bounty ★ PINNED
Documenting all the sources from where I'm learning Mobile(adnroid/IOS) bug bounty so if another researcher want to start with mobile bug bounty he/she don't struggle for resources
Shell ★ 58 2mo agoExplain → -
AutoTabSorter-BurpSuiteExtension
A Burp Suite extension that automatically categorizes HTTP requests from proxy history based on user-defined keywords.
Python ★ 11 10mo agoExplain → -
Terminal-In-Burpsuite-BurpSuiteExtension
operate terminal directly form burpsuite
Python ★ 8 7mo agoExplain → -
CustomPayloads-Wordlist.com
Loading all my favorite Payloads and WordList for Fuzzing
Python ★ 8 5mo agoExplain → -
LinkFinder-Web-Version
LinkFinder Web offers the functionality of the CLI tool in a user-friendly web interface. Extract links, endpoints, and JavaScript resources from web pages effortlessly, whether analyzing single pages or crawling entire sites. Simplify your web analysis with LinkFinder Web.
Python ★ 6 1y agoExplain → -
APKDig
A script to extract potentially sensitive files (like .env, .json, .db, etc.) from APKs or decompiled APK folders to organized directories for analysis.
Rust ★ 5 7mo agoExplain → -
Bash-Series
Learn Bash for CyberSec
Shell ★ 4 2y agoExplain → -
BurpsuiteCoolExtensions
No description.
Python ★ 3 10mo agoExplain → -
Random-Codes
All Random Codes which I use to Have Fun in Boring Time I here Check It Out fella
C++ ★ 3 10mo agoExplain → -
Tor-IP-Changer-Script
Tor IP Changer Script is a Python utility designed to automate the process of changing your IP address through the Tor network.
Python ★ 2 10mo agoExplain → -
ws-treasure-hunt
No description.
HTML ★ 2 4mo agoExplain → -
raunakwebsite
No description.
HTML ★ 2 1y agoExplain → -
Problem-Questions-and-Patterns-In-C-CPP-JAVA
Keep learning
C++ ★ 2 2y agoExplain → -
Love_of_Code_Series
In This repository We'll going to store all the Codes related to Our Love of Code series so others can access all the code after Livestream.
C++ ★ 2 2y agoExplain → -
Java-Series
Learn Java for CyberSec
Java ★ 2 2y agoExplain → -
Assignment_Sheets
In this Repo I have 3 Assignment Sheets, C, C++, DSA in C. I got all three programming sheets from my university. Fell free to provide more efficient code for any problem
C ★ 2 2y agoExplain → -
All-CTF-Challenges-Walkthrough
No description.
CSS ★ 2 2y agoExplain → -
endpointer
No description.
Go ★ 2 1y agoExplain → -
My-SSRF-Learning-Notes
No description.
★ 1 1mo agoExplain → -
VirusTotal-Recoon
No description.
Python ★ 1 6mo agoExplain → -
Elite-Burp-Suite-HTTP-History-Analyzer
No description.
HTML ★ 1 7mo agoExplain → -
analyze_manifest
A powerful tool for analyzing Android manifest files, identifying security vulnerabilities, and extracting deep links with colorful console output.
Python ★ 1 7mo agoExplain → -
vibe-coded-ssrf-tool
JavaScript files for SSRF-prone endpoints and parameters. Supports passive extraction with likelihood scoring and an optional active testing module with a comprehensive payload matrix.
Python ★ 1 1mo agoExplain → -
godot-mcp-server
Production-grade Model Context Protocol server for controlling the Godot 4.x game engine from any MCP client (opencode, Claude, VS Code, etc.).
TypeScript ★ 1 1mo agoExplain → -
Thick-Client-Pentesting-On-MacOS
A comprehensive reference for thick client pentesting on macOS, synthesized from CyberArk Labs research (Parts 1–3) and community writeups. Covers everything from app structure to dylib hijacking and XPC attacks
HTML ★ 1 2mo agoExplain → -
Creating_Telegram_Bot
No description.
Python ★ 1 4mo agoExplain → -
Tracking-Gym-Weights-and-Exercise
No description.
HTML ★ 1 4mo agoExplain → -
Docker-Learning-Project
No description.
HTML ★ 1 4mo agoExplain → -
ShodanX-BB-Tools ⑂
ShodanX is a tool to gather information of targets using shodan dorks⚡.
★ 1 2y agoExplain → -
Tor-IP-Changer-BurpSuiteExtension-Incomplete
A collection of powerful Burp Suite extensions designed to enhance security testing workflows and automate common tasks.
Python ★ 1 10mo agoExplain → -
PullAPKFromPure
Pull apk from apkpure for pentesting or bug bounty purpsose
Python ★ 1 7mo agoExplain → -
Research-Papers-By-B1scuit
Repository for storing and showcasing my research papers.
★ 1 10mo agoExplain → -
subdomain-overtake
No description.
HTML ★ 1 11mo agoExplain → -
BugBoard-BB-Tools ⑂
A comprehensive open-source cybersecurity tool for vulnerability detection and bug hunting.
★ 1 1y agoExplain → -
Python-Series
Learn Python for CyberSec
Python ★ 1 2y agoExplain → -
Pooortfolio-Site
No description.
HTML ★ 1 1y agoExplain → -
SecretFinder-BB-Tools ⑂
SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files
Python ★ 1 1y agoExplain → -
PHP-Series
Learn PHP for CyberSec
PHP ★ 1 2y agoExplain → -
Extr-Real-time-HTTP-Logger
No description.
Java ★ 0 1d agoExplain → -
Raunaksplanet
No description.
HTML ★ 0 2d agoExplain → -
AndroBoomer
Automates APK analysis by fetching apps or using local APKs and running multiple reverse‑engineering and security tools either individually or in parallel, with organized per‑tool outputs.
Shell ★ 0 7mo agoExplain → -
wcDetect-BB-Tools ⑂
web cache deception detect
★ 0 8mo agoExplain → -
GitHub-Repository-Reconnaissance-Tool
A security tool for scanning Git repositories to find secrets, deleted files, and sensitive information.
Python ★ 0 8mo agoExplain → -
Bruteforce-JWT-Secret
Simple script to bruteforce JWT Seceret with wordlist
Python ★ 0 7mo agoExplain → -
Learn-Thick-client-bug-bounty
Check my gitbook for resources
★ 0 7mo agoExplain → -
Learn-Kernel-Bug-Bounty
No description.
★ 0 22d agoExplain → -
WiFi-Security-Pentesting-Learning-Notes
Personal documentation of my WiFi security research
★ 0 1mo agoExplain → -
JAR-Reverse-Engineering-Tool
No description.
Python ★ 0 1mo agoExplain → -
Sample-Repo-For-POC-Testing-Purpose
No description.
HTML ★ 0 1mo agoExplain → -
xcode-mcp-server
MCP (Model Context Protocol) server that bridges AI assistants with Xcode, enabling full control over Xcode projects, builds, simulators, testing, and debugging — all without touching Xcode manually.
TypeScript ★ 0 1mo agoExplain → -
bug-bounty-hunting-ai ⑂
Demo code and presentation materials for the talk "Bug Bounty Hunting with AI Agents" at Basel One 2025.
★ 0 9mo agoExplain → -
RAG-Based-AI-Chatbot-for-Organization-API-Docs
Simple AI chatbot for API documentation using RAG + local LLMs with Ollama. Fully self-hosted, no cloud APIs.
Python ★ 0 2mo agoExplain → -
Void ⑂
a 3D vulkan game engine which is leveraging new graphics techniques to make a game.
★ 0 3mo agoExplain → -
Nmap-Visualizer-For-Noobs
No description.
HTML ★ 0 3mo agoExplain → -
Demo-Repo-For-CoderabbitAI
No description.
Python ★ 0 4mo agoExplain → -
PayloadsAllTheThings ⑂
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
★ 0 2y agoExplain → -
hakrevdns-BB-Tools ⑂
Small, fast tool for performing reverse DNS lookups en masse.
Go ★ 0 2y agoExplain → -
Task-Ninja ⑂
Ultimate Tasks Automation Framework for Hackers, DevSecOps, Pentesters, and Bug-bounty hunters!
★ 0 10mo agoExplain → -
PullAllAPKs
boomer_andro is a smart command-line tool that makes downloading Android APKs easy. It wraps around the apkeep utility with a simpler interface and intelligent features.
Shell ★ 0 7mo agoExplain → -
apk2url-BB-Tools ⑂
An OSINT tool to quickly extract IP and URL endpoints from APKs by disassembling and decompiling
Shell ★ 0 7mo agoExplain → -
back-me-up-BB-Tools ⑂
This tool will check for Sensitive Data Leakage with some useful patterns/RegEx. The patterns are mostly targeted on waybackdata and filter everything accordingly.
Shell ★ 0 7mo agoExplain → -
rep-BB-Tools ⑂
rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks
★ 0 7mo agoExplain → -
Sonic-PI-Codes
No description.
Ruby ★ 0 7mo agoExplain → -
BlogsCompanyWise
No description.
JavaScript ★ 0 7mo agoExplain → -
Practice-Blogging-Site
No description.
CSS ★ 0 7mo agoExplain → -
hacker-writeups.github.io
hacker-writeups.github.io
★ 0 9mo agoExplain → -
Broken-Link-Hijacker-BB-Tools
No description.
Python ★ 0 8mo agoExplain → -
JSMap-Inspector-BB-Tool ⑂
**A powerful, offline, single-file HTML tool designed for developers and security researchers to inspect and analyze JavaScript Source Map (`.js.map`) files.**
★ 0 9mo agoExplain → -
APK-s-For-BugBounty
My android bug bounty target
★ 0 9mo agoExplain → -
sqrsec.com-API_Fuzzing_Lists
SquareSec's API Fuzzing Lists is a comprehensive collection of 9 wordlists tailored for API reconnaissance. Compiled from over 120,000 public API documentations, it includes:
★ 0 10mo agoExplain → -
Latex-Code-To-PDF
pdflatex file.tex
TeX ★ 0 10mo agoExplain → -
TOR-Proxy-Chain-Script-Incomplete
No description.
Python ★ 0 10mo agoExplain → -
bbot-BB-Tools ⑂
The recursive internet scanner for hackers. 🧡
★ 0 11mo agoExplain → -
Websites-Developed-ByAI
Multiple Single page websites developed by opensource LLM models.
HTML ★ 0 10mo agoExplain → -
PNG-OCR-Side-Project
PNG OCR - Side Project is a lightweight, client-side web tool that extracts text from PNG images entirely in the browser using Tesseract.js. It supports drag-and-drop, language selection, progress display, and allows users to copy or download the extracted text while keeping all data private.
JavaScript ★ 0 10mo agoExplain → -
CVSS-Calculator-BurpSuiteExtension
A modern Burp Suite extension that calculates CVSS v3.1 Base Scores with a clean, professional interface.
Python ★ 0 10mo agoExplain → -
download-directory.github.io ⑂
Web App: Download just a sub directory from a GitHub repo.
★ 0 1y agoExplain → -
domloggerpp-BB-Tools ⑂
A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
★ 0 11mo agoExplain → -
apk_sec_scanner-BB-Tools ⑂
No description.
Python ★ 0 11mo agoExplain → -
AndroidNativeScanner-BB-Tools ⑂
Analyze Android native `.so` files
★ 0 1y agoExplain → -
get_schemas-BB-Tools ⑂
Print out URL schemas from an Android app
★ 0 1y agoExplain → -
proxmark3-FRID-Card-Pentesting ⑂
Iceman Fork - Proxmark3
★ 0 1y agoExplain → -
unwebpack-sourcemap-BB-Tools ⑂
Extract uncompiled, uncompressed SPA code from Webpack source maps.
★ 0 4y agoExplain → -
CloneAllRepo
clone_repos.sh is a lightweight Bash script that automates cloning of all public repositories from a GitHub profile or organization. It takes a GitHub URL as input, handles up to 500 repos, skips existing ones, and requires no authentication. Ideal for backups, audits, or offline access.
Shell ★ 0 1y agoExplain → -
30X-BB-Tools ⑂
This script provides various ways to create HTTP redirects from 301 to 308, useful for stuff like SSRF
JavaScript ★ 0 1y agoExplain → -
Android-Deeplink-Parser-BB-Tools ⑂
No description.
Python ★ 0 1y agoExplain → -
AndroidExportViewer
A simple Python script to list all exported components and check their protection levels for further penetration testing.
HTML ★ 0 1y agoExplain → -
frida-script-gen-BB-Tools ⑂
Generate Frida bypass scripts for Android APK root and SSL checks.
★ 0 1y agoExplain → -
mobapp-storage-inspector-BB-Tools ⑂
A tool for inspecting and analyzing mobile application storage files.
★ 0 1y agoExplain → -
MobApp-DataExtractor-BB-Tools ⑂
A tool for listing and extracting installed Android APKs and decrypted iOS IPAs (plus app storage) from rooted or jailbroken devices.
★ 0 1y agoExplain → -
apk-components-inspector-BB-Tools ⑂
A lightweight Python-based tool to extract and enumerate Android components and automatically generate practical ADB commands
★ 0 1y agoExplain → -
DecompileAllAPK-s
Decompile multiple apks at once with simple python script
Python ★ 0 1y agoExplain → -
exif-samples-BugBounty ⑂
Sample images for testing Exif metadata retrieval.
★ 0 1y agoExplain → -
EmailFinder.gitt-BB-Tools ⑂
No description.
★ 0 2y agoExplain → -
Super-Interesting-Repo ⑂
No description.
★ 0 1y agoExplain → -
Subdominator-BB-Tools ⑂
SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty
★ 0 1y agoExplain → -
jwt-secrets-BB-Wordlist ⑂
No description.
★ 0 2y agoExplain → -
subfinder-BB-Tools ⑂
Fast passive subdomain enumeration tool.
★ 0 2y agoExplain →
No repos match these filters.