Skip to content
View Vulnpire's full-sized avatar
💢
../../../../../$(echo ${USER:0:2}.$(uname -n | cut -c1-4).127.0.0.1 | base64)
💢
../../../../../$(echo ${USER:0:2}.$(uname -n | cut -c1-4).127.0.0.1 | base64)

Block or report Vulnpire

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Vulnpire/README.md

V // Vulnpire

security research · AI engineering · builder

Vulnspire Cyberpars

v1xtron Vulnpire cyberpunk terminal

I build security systems for authorized web testing — part researcher, part engineer, always looking for the signal others missed.

whoami

Animated Vulnpire terminal showing v1xtron's identity

open the terminal output
handle     : v1xtron
callsign   : V
mode       : confident, curious, diligent, always learning
focus      : security research / AI engineering / developer tooling
sidequests : bug bounty / CTFs / reversing / strange systems

I’m V, online as v1xtron. My work sits where application security, automation, and developer tooling overlap. I like turning vague signals into clean explanations, reproducible findings, and stronger defenses.

workbench

Project Role / direction
Vulnspire Building an AI-native PTaaS for continuous, authorized web security validation.
Cyberpars Cybersecurity Co-founder delivering penetration testing, red-team work, and security services.
Independent research Bug bounty work, vulnerability research, tooling, and technical experiments.

track record

Marker Detail
7+ years Offensive security, penetration testing, and vulnerability research.
200+ Security assessments, penetration tests, and adversary-simulation engagements.
1,000+ Valid vulnerability reports across authorized programs, including duplicates.
100+ Organizations reached through assessments, disclosure, and security research.

focus

Area What I work on
Web, API & AI security Authentication, authorization, business logic, API workflows, LLM application surfaces, and browser-backed validation.
Internal & Active Directory Attack-path mapping, privilege boundaries, lateral-movement analysis, and defensive recommendations.
Red team operations Adversary simulation, control validation, threat-informed testing, and purple-team feedback.
Cloud & infrastructure AWS, GCP, Azure, containers, Linux, exposed assets, and configuration review.
Recon & automation OSINT, attack-surface mapping, discovery pipelines, HTTP analysis, and repeatable tooling.
Reverse engineering Binary behavior, malware analysis, protocol inspection, debugging, and forensic research.

inside vulnspire

┌─ the direction ────────────────────────────────────────────────────┐
│ AI agents · browser validation · web/API security · durable evidence │
│ reproducible proof · findings pipelines · secure automation          │
└─────────────────────────────────────────────────────────────────────┘

I’m building Vulnspire around a simple idea: let automation handle the repetitive work, while every important claim stays tied to something a browser actually did.

build log

Project Focus
Vulnspire AI-native PTaaS, autonomous discovery, browser proof, evidence, and findings workflows.
Banshee-AI AI-assisted OSINT, reconnaissance, and attack-surface discovery.
Arsenal Security tools, scripts, templates, and field notes.
Wayfuzz Focused wordlist generation from archived web paths.

toolkit

Languages · Go · Python · TypeScript · JavaScript · Bash · PowerShell · Rust · C/C++ · SQL

Security · Burp Suite · Ghidra · Frida · Wireshark · Nmap · BloodHound · Impacket · Playwright

Systems · Linux · WSL · Docker · Kubernetes · AWS · GCP · Azure · CI/CD

side quests

  • Bug bounty: keep looking after the workday ends; the best leads are often the quiet ones.
  • CTFs: reversing, exploitation, and odd systems for the fun of solving hard problems.
  • Learning: learn → explore → build → test → share → repeat.

I’m deliberate with details, comfortable with hard problems, and happiest when a vague signal becomes a result someone else can verify.

operator_console

v1xtron Vulnpire operator console visual

A visual study of a proof-first control plane: quiet interface, sharp edges, no theatrics.

topics I keep returning to

Web and API security · AI security · vulnerability research · automation · reconnaissance · threat hunting · reverse engineering · detection engineering · DevSecOps · adversary emulation · open-source tooling


Vulnpire · sharp eyes · clean proof

Pinned Loading

  1. Arsenal Arsenal Public

    Collection of tools, scripts, one-liners, templates, dorks and more

    Shell 12 3

  2. Banshee-AI Banshee-AI Public

    AI-powered high‑speed Google & Brave dorking tool for reconnaissance and OSINT.

    Go 6

  3. bounty-search-engine bounty-search-engine Public

    This search engine automates the discovery of sensitive information using customized dorks across GitHub, Google, and Shodan.

    JavaScript 16 7

  4. Reclaim Reclaim Public

    Identify potential subdomain takeover vulnerabilities by checking CNAME records and verifying exploitability through HTTP responses

    Go 4

  5. rHunter rHunter Public

    Open Redirect Hunter is a Burp Suite extension designed to automatically detect open redirect vulnerabilities in web applications.

    Python 6

  6. sXtract sXtract Public

    Fetch IP addresses from Shodan search results.

    Go 3