Skip to content
View badchars's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report badchars

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
badchars/README.md

Hi, I'm Orhan

Washington DC, USA · Offensive Security · Author: Agentic AI for Offensive Cybersecurity

EmailWebsiteMediumLinkedInBuy Me A CoffeeCharity

HackerOneBugcrowdCobaltOWASP

PythonJavaScriptTypeScriptAWSAzureBurp SuiteClaudeMCP

Building AI-powered security tools at the intersection of penetration testing and agentic AI.


Current Projects

ProjectDescription
CyberStrikeAI-powered offensive security agent — autonomous pentesting, 4 specialized agents, 120+ OWASP test cases
recon0All-in-one bug bounty recon pipeline — 9-stage, resumable, LLM-enriched
nMapperAutomated penetration testing tool with speech recognition
AzureAD-PentestAzure Active Directory penetration testing methodology and tooling
osint-mcpOSINT intelligence MCP — 37 tools, 12 sources. Shodan, VirusTotal, Censys, SecurityTrails, DNS recon, WHOIS, certificate transparency, BGP, Wayback Machine
supply-chain-mcpSupply chain security MCP — 90 tools, 21 sources. OSV, GHSA, NVD, EPSS, CISA KEV, npm, PyPI, crates.io, Go, RubyGems, NuGet, Packagist, deps.dev, Scorecard, Rekor
darknet-mcpDark web intelligence MCP — 66 tools, 16 sources. Breach data, ransomware tracking, Tor .onion, malware analysis, blockchain intel, exploit search
hackbrowser-mcpBrowser MCP for security testing — 39 tools, multi-container Firefox, injection testing
cloud-audit-mcpCloud security audit MCP — 38 tools, 60+ checks across AWS, Azure, GCP
github-security-mcpGitHub security posture MCP — 39 tools, 45 checks across org, repos, Actions, secrets, supply chain
cve-mcpCVE/vulnerability intelligence MCP — 23 tools, 5 sources (NVD, EPSS, KEV, GHSA, OSV), risk scoring
dns-security-mcpDNS security intelligence MCP — 104 tools, 13 categories. DNSSEC validation, hijacking detection, tunneling analysis, typosquatting, email security, certificate transparency, blocklist checking. Zero API keys required
satellite-mcpFull-spectrum GEOINT MCP — 171 tools, 27 categories. Satellite imagery, aircraft tracking, maritime surveillance, military intelligence, conflict monitoring, space tracking, environmental analysis, sanctions compliance, cyber-geo intel
steganography-mcpSteganography analysis MCP — 128 tools, 12 categories. LSB detection, chi-square steganalysis, RS analysis, JPEG/F5/JSteg/OutGuess detection, BPCS, video & GIF stego, network covert channels, MP3 stego, spread spectrum, archive stego, QR code analysis. Zero API keys
mcp-security-scannerMCP server security scanner — 55 tools. Runtime inspection, AST-based SAST, config audit, dependency analysis, OWASP MCP Top 10 compliance, prompt injection testing
living-off-the-land-lolbins-mcpLiving off the Land LOLBins MCP — 59 tools, 10 catalogs (GTFOBins, LOLBAS, LOOBins, LOLDrivers, LOLRMM, WADComs). Privilege escalation, persistence, evasion, detection engineering, ATT&CK mapping
fingerprint-mcpDigital fingerprinting MCP — 13 tools, 103 techniques. TCP/TLS/SSH/HTTP/DNS/WAF/IoT fingerprinting, JA4/JARM, C2 detection, OSINT enrichment
ai-knowledge-graphInteractive AI/ML knowledge graph — 132 terms, 531 relationships, 11 categories, 6 languages

Breaking things to make them stronger. Finding vulnerabilities so others can fix them.

GitHub Activity Graph

Pinned Loading

  1. awesome-pythonawesome-pythonPublic

    Forked from vinta/awesome-python

    A curated list of awesome Python frameworks, libraries, software and resources

    Python

  2. nMappernMapperPublic

    nMapper is an automated penetration testing tool. (speech recognition included!)

    Shell 2