This is your work, valued

New York

TobiasGuta

Advanced
@tobiasGuta

I'm ready, I prove it by breaking down complex systems and securing them.

Next.js-RSC-RCE-Scanner-Burp-Suite-Extension. Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

24

GeminiTerminal. GeminiTerminal: A command-line interface (CLI) tool for seamless interaction with Google’s Gemini AI. Easily chat, troubleshoot, and receive helpful responses directly from your terminal. Powered by generative AI, GeminiTerminal offers a simple and effective way to engage with advanced AI models

8

FTPHunter. FTPHunter is a powerful and efficient tool designed for FTP server enumeration and vulnerability assessment. It allows security professionals and penetration testers to quickly discover key information about FTP servers, such as anonymous login capabilities, file access permissions, server banners, and more.

6

sub-enum. This tool is designed to automate the discovery of subdomains for a given domain

4

StealthCommand. A Python TCP server that listens for incoming client connections, executes shell commands, and returns the output. It runs as a daemon, handling multiple clients with threads

3

SwaggerHunter. A Swagger/OpenAPI enumerator and lightweight endpoint probing tool. Automatically parses Swagger/OpenAPI specifications, lists all API endpoints, applies optional filters (HTTP methods, limits)

3

RssTool2.0. RSSBot Elite delivers real-time RSS and YouTube feed notifications across multiple Discord channels, each with custom categories and smart webhook routing.

3

sniff. A lightweight packet sniffer for Windows and Linux that captures Layer 2 (Ethernet) packets, displaying detailed hex and ASCII output. It supports sniffing on any network interface and saves packets to a PCAP file for analysis.

3

JS-Miner-Pro-Burp-Suite-Extension. JS Miner Pro is a lightweight, customizable Burp Suite extension designed to find hard-coded secrets, API endpoints, and hidden paths inside JavaScript, JSON, and HTML files.

3

TheLogRipper. PowerShell tool for interactive Windows Event Log analysis. Extracts, highlights, and flags suspicious activity from .evtx files with export support. Built for threat hunters, SOC analysts, and DFIR ops.

2

Myownshell. Myownshell is a web-based terminal emulator with a sleek. It allows users to execute commands directly from their browser, complete with a Discord webhook-based authentication system for secure access.

2

Spring-Boot-Actuator-Hunter-Burp-Suite-Extension. A lightweight, high-speed Burp Suite extension designed to detect exposed Spring Boot Actuator endpoints. It automatically fuzzes target applications for sensitive administrative paths that can leak environment variables, API mappings, and routing configurations.

2

Detective. This tool is designed to monitor the targets of your bug bounty programs, For example, it will alert you if new domains appear. It does this by running scans on the domains you specify, comparing them with those stored in the database. If a new domain is found, it will notify you and send you an alert.

1

BashReconKit. This tool is a command-line based network reconnaissance tool with various functionalities useful for information gathering and vulnerability assessment in the context of cybersecurity.

1

MonitorTool. These tools are used for penetration testing.

1

ffufGemini. This Python script automates web application fuzzing using ffuf, with Gemini AI-powered file extension suggestions. It detects technologies on the target website with httpx, uses Gemini's AI to suggest file extensions based on those technologies, and runs ffuf to discover potential hidden files.

1

Canvas-Fingerprint-Blocker-Modified. This extension prevents HTML canvas element from generating a unique identification key to protect user's privacy. It works by adding slight noise to the canvas data, making the fingerprint inconsistent and unique for each session.

1

Race-Condition-Gate. A Synchronization Tool for testing Time-of-Check to Time-of-Use (TOCTOU) Vulnerabilities

1

403-Forbidden-Buster. An Automated 403 Bypass Fuzzer for Burp Suite Community & Professional

1