Skip to content
View riteshekbote's full-sized avatar
😇
😇

Block or report riteshekbote

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
riteshekbote/README.md

Ritesh Ekbote

Bug bounty hunter · Security researcher · Automation engineer

I build automated systems that perform continuous, authorized security research — multi-model AI pipelines, target inventory, recon, lead discovery, triage, and verification — orchestrated with GitHub Actions.


What I Build

Software that turns bug-bounty hunting into a repeatable, measurable engineering discipline instead of a series of manual clicks:

  • Autonomous hunting pipelines — scheduled, multi-model agents that move through recon → surface → hypothesis → triage → verification, one phase per cycle, with state and a shared knowledge base.
  • Multi-model analysis — prompt-driven analyst, triager, and verifier roles; outputs are ranked by confidence and gated through a 7-Question validation gate before anything is reported.
  • Passive-first, scope-bound testing — every pipeline is bound to an explicit authorized scope, uses GET/HEAD/OPTIONS-only probes where rules require it, and enforces rate limits, politeness budgets, and 403/429 grace-stops.
  • Target inventory & verification — per-target asset lists, live-host checks, and an honest distinction between leads (candidate findings) and validated bugs.

The *-hunt repositories are concrete deployments of this model against specific authorized bug-bounty programs.

Featured Projects

Project Description
DedupeAI Burp Suite (Montoya) extension: deduplicates HTTP history into an AI-ready unique-request feed, color-codes attacker/victim traffic by listener port, and ships the set to Claude Code — built for multi-account IDOR/BOLA testing.
oniontui Terminal AI assistant that browses and searches the web — including .onion hidden services — through Tor, with plan-first agents, working memory, and circuit rotation.
Js-Scanner AI-powered JS security audit tool: crawls a site's scripts, extracts endpoints/secrets/JWTs, and produces an interactive report.
gladia-hunt 24/7 multi-model bug-hunting automation bound to the Gladia authorized scope.
threema-hunt 24/7 passive, read-only multi-model hunting pipeline for the Threema program.

Research Areas

Web2 · IDOR · broken access control · auth/ATO chains · business logic · SSRF · injection

Mobile · Android/iOS app assessment (jadx, Frida, objection, MobSF)

AI/LLM · prompt injection · RAG/vector-store poisoning · agentic AI security (ASI01–ASI10)

Web3 · smart-contract auditing (Foundry, Slither, Echidna)

Cloud / infra · AWS/GCP/K8s misconfiguration · post-credential privilege analysis

Automation & Tooling

GitHub Actions · opencode multi-model agents · Python · recon (subfinder, dnsx, httpx) · Burp Suite / Montoya · Frida · jadx · Foundry · Slither · orchestrating scheduled, stateful, verifiable research.

How I Work

  1. Scope first — every pipeline is bound to an explicit authorized target with exclusions and safe defaults.
  2. Passive before active — read-only probes where program rules require it.
  3. Leads ≠ findings — candidate hypotheses are triaged by a second model and validated before reporting.
  4. Humans decide — models propose; I verify and submit.

Activity

Hack legally. Report responsibly. 🔒

📊 Live Stats

Metric Value
Followers 5
Public repos 70
Total stars 8

Recently updated:

  • roobet-hunt — 24/7 deep bug-hunting automation for Roobet (bugs.olivermaicher.eu)
  • hornbach-hunt — 24/7 deep bug-hunting automation for HORNBACH Holding AG & Co. KGaA / HORNBACH Group (bugs.olivermaicher.eu)
  • daimler-truck-hunt — 24/7 deep bug-hunting automation for Daimler Truck Holding AG (bugs.olivermaicher.eu)
  • questnet-gmbh-hunt — 24/7 deep bug-hunting automation for Questnet GmbH (bugs.olivermaicher.eu)
  • obi-hunt — 24/7 deep bug-hunting automation for OBI Group Holding SE & Co. KGaA (bugs.olivermaicher.eu)

Last refreshed: 2026-09-03 08:52 UTC — auto-updated daily by GitHub Actions (.github/workflows/profile-stats.yml)

Popular repositories Loading

  1. gladia-hunt gladia-hunt Public

    24/7 multi-model bug-hunting automation bound to the authorized Gladia bug-bounty scope.

    Python 3 1

  2. DedupeAI DedupeAI Public

    Burp Suite (Montoya) extension: dedupe HTTP history into an AI-ready unique feed, tag attacker/victim by listener port, and ship the set to Claude Code for IDOR/BOLA testing.

    Java 1 3

  3. spare-hunt spare-hunt Public

    24/7 multi-model bug-hunting automation bound to the Spare authorized scope (spare.com and platform/api/routing forms).

    Python 1

  4. threema-hunt threema-hunt Public

    24/7 passive, read-only multi-model hunting pipeline for the Threema bug-bounty program, gated by scope and 7-question validation.

    Python 1

  5. signageos-hunt signageos-hunt Public

    24/7 multi-model bug-hunting automation bound to the signageOS authorized scope (box.signageos.com).

    Python 1

  6. oniontui oniontui Public

    Tor-powered terminal AI assistant that browses and searches the web, including .onion hidden services, with plan-first agents, working memory, and circuit rotation.

    Python 1