Personal Projects & Toolkits
Security research & browser-based tools for offensive security.
SPF Detector
Validate email security configurations and analyze Sender Policy Framework records.
/tools/spfrecordchecker/SSL Certificate Analyzer
Analyze weak hashes, expiry, wildcards and issuers from nmap --script ssl-cert output.
/tools/weaksslcerts/Weak SSL Cipher Analyzer
Analyze weak SSL ciphers and protocols from Nmap scan results.
/tools/weaksslciphers/SSH Security Analyzer
Analyze SSH configurations or Nmap scans for cryptographic risks.
/tools/sshsecurity/JS SourceMap Unmapper
Recover the original source tree from a .map file, then scan it for leaked secrets and endpoints.
/tools/sourcemapunmapper/JWT Analyzer
Decode, audit, forge and bruteforce JSON Web Tokens — six tools in one.
/tools/jwtauditor/Google / Gemini API Key Checker
Test a leaked API key against Gemini and Google services to determine its scope and enabled permissions.
/tools/googleapikeychecker/Web Archive URL Fetcher
Fetch archived records with status 200 for a domain, straight from the Wayback Machine.
/tools/webarchive/Nmap Result Parser
Extract IP, port and service version from scan output to surface version disclosure.
/tools/nmapresultparser/Nmap Result Sorting Kit
Sort and search Nmap scan results to pull out the hosts and ports you care about.
/tools/nmapsortingkit/COOP Tabnabbing PoC
Show that a window opened without Cross-Origin-Opener-Policy can be navigated away by whoever opened it.
/tools/coop/AI-Powered Proofreader
Check grammar, spelling, punctuation and style with two independent engines.
/tools/proofreader/SourceMap Radar
Browser extension that auto-scans every page for exposed .map files and verifies which are retrievable.
/tools/sourcemapradar/Asgard Magic Importer
Browser extension that imports a drafted finding straight into the Asgard New Finding form — every field and Evidence record, in one click.
/tools/asgardmagicimporter/PH Mobile Number Generator
Python script that generates test mobile numbers across Globe, Smart and DITO prefixes.
/tools/phmobilenumbergenerator/Lazymap
One command that chains selected Nmap NSE scripts, sslscan, ssh-audit, dig, ldapsearch, rpcclient, PRET and more across a host or a list of them.
/tools/lazymap/SegIt!
Automates network segmentation testing: scans the ranges that are meant to be unreachable and reports whatever answers back.
/tools/segit/