Skip to content
View tobiasGuta's full-sized avatar
🏠
Working from home
🏠
Working from home
  • New York

Highlights

  • Pro

Block or report tobiasGuta

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tobiasGuta/README.md

Tobias GitHub Header

Security research focus


Cybersecurity student and open-source builder creating practical tools for bug hunters and security researchers.



Profile views


Mission

Web Security Bug Bounty Recon Automation Vulnerability Research Reverse Engineering

New York-based cybersecurity student focused on offensive security, web application testing, reconnaissance automation, and vulnerability research.


About Me

I am a security researcher, bug hunter, and open-source builder focused on web application security, reconnaissance automation, and vulnerability research.

I design practical security tools that help researchers organize evidence, understand application behavior, automate repetitive workflows, and perform repeatable human-led testing.

My long-term goal is to become a professional vulnerability researcher, contribute meaningful open-source security tooling, and discover vulnerabilities in real-world software.

Developer animation

Featured Security Projects

Human-led reconnaissance orchestration platform built for repeatable, scope-aware security workflows.

Recon Automation Security Workflows

View repository →

Content-discovery engine designed for structured fuzzing, wildcard detection, evidence collection, and security research.

Go Fuzzing CLI

View repository →

Chrome DevTools extension for studying application states, user workflows, network requests, and authorization behavior.

JavaScript Chrome Extension Web Security

View repository →

Local HackerOne report backup and synchronization tool with update detection and attachment management.

Python HackerOne Data Sync

View repository →

Security intelligence platform for collecting, normalizing, correlating, and presenting vulnerability information.

Security Intelligence Vulnerabilities Platform

View repository →

Security utility for discovering and analyzing exposed Swagger and OpenAPI documentation during authorized testing.

API Security OpenAPI Recon

View repository →

Explore all repositories →


Technical Arsenal

Core Development

Programming languages

Platforms and Engineering

Platforms and engineering tools

Security Focus

Web Application Security API Security Reconnaissance Bug Bounty Vulnerability Research Reverse Engineering

Research Interests

Web Security Vulnerability Research Reverse Engineering
Authentication and authorization Open-source vulnerability discovery Windows applications
Business logic vulnerabilities Secure code review Browsers
API security Fuzzing and crash analysis Network services
Race conditions Vulnerability intelligence IoT firmware
Reconnaissance automation Exploit-development fundamentals Malware analysis

Activity Graph

GitHub activity graph

Beyond the Hunt

While my main focus is security, I am a builder at heart.

I believe security tooling should be practical, transparent, and accessible. The best automation does not replace the researcher—it removes repetitive work, preserves evidence, and gives the researcher more time to think.

I am a strong supporter of open-source software, continuous learning, and sharing useful tools with the wider security community.

I hope you find something valuable in my repositories. Contributions, collaboration, constructive feedback, and security discussions are always welcome.

See you around!

GitHub profile Explore projects



Cybersecurity footer banner


Footer wave

Popular repositories Loading

  1. Next.js-RSC-RCE-Scanner-Burp-Suite-Extension Next.js-RSC-RCE-Scanner-Burp-Suite-Extension Public

    Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

    HTML 23 2

  2. Blueprint-App-AI Blueprint-App-AI Public

    Blueprint App is an AI-assisted electronics design tool for turning a plain-English hardware idea into a structured electronics blueprint.

    HTML 13 2

  3. GeminiTerminal GeminiTerminal Public

    GeminiTerminal: A command-line interface (CLI) tool for seamless interaction with Google’s Gemini AI. Easily chat, troubleshoot, and receive helpful responses directly from your terminal. Powered b…

    Python 9 2

  4. FTPHunter FTPHunter Public

    FTPHunter is a powerful and efficient tool designed for FTP server enumeration and vulnerability assessment. It allows security professionals and penetration testers to quickly discover key informa…

    Python 6

  5. sub-enum sub-enum Public

    Forked from NB071/sub-enum

    This tool is designed to automate the discovery of subdomains for a given domain

    Python 4

  6. JS-Miner-Pro-Burp-Suite-Extension JS-Miner-Pro-Burp-Suite-Extension Public

    JS Miner Pro is a powerful, customizable Burp Suite extension designed to find hard-coded secrets, API endpoints, and hidden paths inside JavaScript and JSON files.

    Java 4