Skip to content
View bess1lie's full-sized avatar
💤
💤

Block or report bess1lie

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
bess1lie/README.md

bess1lie banner

Site GitHub Email

security engineer · recon · api security · graphql

About

Security engineer focused on recon automation, API security, and GraphQL attack-surface analysis.

I build detection-first tooling for security research and validation workflows. My projects are scoped, transparent, and designed for visibility rather than exploitation.

detection-first · scope-aware · open-source

What I build

I design tools that help security teams understand exposure, validate assumptions, and map risk across APIs and GraphQL surfaces.

  • Recon automation and workflow orchestration
  • API security analysis and auditing
  • GraphQL schema inspection and risk classification
  • Attack-surface discovery with scope-aware controls
  • Open, inspectable output formats for research and validation

Featured projects

apihunter

REST API security CLI for discovery, auth auditing, and heuristic checks around IDOR, CORS, and rate-limit issues.

bounthunt

Recon orchestration pipeline built around subfinder, dnsx, httpx, naabu, nuclei, and katana with scope-gated execution and diff monitoring.

gqlhunter

GraphQL recon and risk analysis toolkit with introspection, classification, schema diffing, SARIF output, and dashboard reporting.

Stack

stack

Current focus

  • Hardening gqlhunter SARIF and reporting surfaces
  • Improving dashboard tooling and traceability
  • Researching broken access control and DOM XSS patterns
  • Building safer, more observable security workflows

Principles

  • Detection-first: analysis and recon before exploitation
  • Scope-aware: every request is constrained by allow/deny policy
  • Open formats: SQLite, HTML, Markdown, SARIF
  • Open source: reproducible, inspectable, auditable
  • Security tooling should improve visibility, not increase risk

Links

footer banner

Pinned Loading

  1. bounthunt bounthunt Public

    Bug bounty automation framework — recon orchestration, scope-aware scanning, diff monitoring, checkpoint/resume

    Python 1

  2. gqlhunter gqlhunter Public

    GraphQL recon & analysis CLI — schema discovery, introspection, auth analysis, query variants, risk classification, dashboard

    Python 1

  3. apihunter apihunter Public

    Professional REST API security testing CLI for OpenAPI discovery, authentication analysis, security heuristics and bug bounty reconnaissance.

    Python 1