Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
160 changes: 119 additions & 41 deletions profile/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,118 +2,196 @@

<picture>
<source media="(prefers-reduced-motion: reduce)" srcset="https://raw.githubusercontent.com/Awarexone/.github/main/profile/assets/hero-still.png">
<img src="https://raw.githubusercontent.com/Awarexone/.github/main/profile/assets/hero.png" width="828" alt="AwareXone — building open-source security infrastructure for the AI era">
<img src="https://raw.githubusercontent.com/Awarexone/.github/main/profile/assets/hero.png" width="720" alt="AwareXone — building open-source security infrastructure for the AI era">
</picture>

<br />

# AwareXone

> Building open-source security infrastructure for the AI era.
### Building open-source security infrastructure for the AI era.

We build security tools and services that help developers, security researchers, organizations, and individuals find vulnerabilities, prevent attacks, and protect their digital assets.

<br />

[Website](https://www.awarexone.com) · [Open Source](https://www.awarexone.com/open-source) · [Services](https://www.awarexone.com/services) · [GitHub](https://github.com/Awarexone) · [X](https://x.com/awarexone)

<br />

<sub>Based in Malaysia · Working worldwide</sub>

</div>

---

<div align="center">

## What We Do

### AI & Application Security
</div>

Security tools for AI-built applications, AI agents, APIs, source code, and modern software — so issues are found before they ship.
<br />

### Offensive Security
| Focus | What it means |
| :---- | :------------ |
| **AI & Application Security** | Security tools for AI-built applications, AI agents, APIs, source code, and modern software — so issues are found before they ship. |
| **Offensive Security** | Vulnerability discovery, penetration testing, bug bounty research, and application security testing — against real systems, with written authorisation and agreed scope. |
| **Human & Social Engineering Security** | Defense and training around phishing, vishing, SMiShing, callback phishing, impersonation, and AI/deepfake social engineering — then rebuilding the judgement those attacks depend on. |
| **Digital Protection & Recovery** | Account and social media recovery support, exposure removal, and executive / VIP digital protection. Families are covered as standard. We do not guarantee recovery outcomes. |

Vulnerability discovery, penetration testing, bug bounty research, and application security testing — against real systems, with written authorisation and agreed scope.
---

<div align="center">

### Human & Social Engineering Security
## Pinned Repositories

Defense and training around phishing, vishing, SMiShing, callback phishing, impersonation, and AI/deepfake social engineering — then rebuilding the judgement those attacks depend on.
Our open-source projects on GitHub

### Digital Protection & Recovery
</div>

Account and social media recovery support, exposure removal, and executive / VIP digital protection. Families are covered as standard. We do not guarantee recovery outcomes.
<br />

Based in Malaysia. Working worldwide.
| | Project | Description |
| :-: | :------ | :---------- |
| [![Stars](https://img.shields.io/github/stars/Awarexone/Agentic-Bug-Hunter?style=flat-square&labelColor=0B0912&color=CBA6FF)](https://github.com/Awarexone/Agentic-Bug-Hunter/stargazers) | **[Agentic Bug Hunter](https://github.com/Awarexone/Agentic-Bug-Hunter)** | AI-powered bug bounty hunting toolkit for live applications. |
| [![Stars](https://img.shields.io/github/stars/Awarexone/public-skills-builder?style=flat-square&labelColor=0B0912&color=CBA6FF)](https://github.com/Awarexone/public-skills-builder/stargazers) | **[Public Skills Builder](https://github.com/Awarexone/public-skills-builder)** | Turns public research and write-ups into reusable security skills for AI agents. |
| [![Stars](https://img.shields.io/github/stars/Awarexone/web3-bug-bounty-hunting-ai-skills?style=flat-square&labelColor=0B0912&color=CBA6FF)](https://github.com/Awarexone/web3-bug-bounty-hunting-ai-skills/stargazers) | **[Web3 Bug Bounty AI Skills](https://github.com/Awarexone/web3-bug-bounty-hunting-ai-skills)** | Security skills for smart contracts, DeFi, and Web3 research. |
| [![Stars](https://img.shields.io/github/stars/Awarexone/AXguard?style=flat-square&labelColor=0B0912&color=CBA6FF)](https://github.com/Awarexone/AXguard/stargazers) | **[AXguard](https://github.com/Awarexone/AXguard)** | Scan and fix vulnerabilities in AI-built and vibe-coded apps before they ship. |

---
<div align="center">

## Pinned repositories
<br />

Our pinned open-source projects on GitHub:
**AXguard** secures what you build.
**Agentic Bug Hunter** finds what attackers can exploit.

| Project | Description | |
| --- | --- | --- |
| **[Agentic-Bug-Hunter](https://github.com/Awarexone/Agentic-Bug-Hunter)** | AI-powered bug bounty hunting toolkit that works with or without subscription. | [![Stars](https://img.shields.io/github/stars/Awarexone/Agentic-Bug-Hunter?style=flat-square&labelColor=0B0912&color=CBA6FF)](https://github.com/Awarexone/Agentic-Bug-Hunter/stargazers) |
| **[public-skills-builder](https://github.com/Awarexone/public-skills-builder)** | Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed. | [![Stars](https://img.shields.io/github/stars/Awarexone/public-skills-builder?style=flat-square&labelColor=0B0912&color=CBA6FF)](https://github.com/Awarexone/public-skills-builder/stargazers) |
| **[web3-bug-bounty-hunting-ai-skills](https://github.com/Awarexone/web3-bug-bounty-hunting-ai-skills)** | 18 Claude Code skill files for smart contract security — built from 2,749 Immunefi reports, 681 DeFiHack reproductions, and real hunt experience. | [![Stars](https://img.shields.io/github/stars/Awarexone/web3-bug-bounty-hunting-ai-skills?style=flat-square&labelColor=0B0912&color=CBA6FF)](https://github.com/Awarexone/web3-bug-bounty-hunting-ai-skills/stargazers) |
| **[AXguard](https://github.com/Awarexone/AXguard)** | Open-source AI security tool to scan and fix vulnerabilities in your vibe-coded apps before you ship. AXguard by AwareXone. | [![Stars](https://img.shields.io/github/stars/Awarexone/AXguard?style=flat-square&labelColor=0B0912&color=CBA6FF)](https://github.com/Awarexone/AXguard/stargazers) |
<br />

```text
Build → AXguard → Ship → Agentic Bug Hunter
Public Skills Builder / Web3 Skills
```

</div>

---

<div align="center">

## Cybersecurity Services

AwareXone also works directly with organizations and individuals.
Work directly with organizations and individuals

</div>

### Social Engineering Defense
<br />

We run the attacks your staff will really face — the phone call, the invoice, the cloned voice, the service desk reset — then rebuild the judgement those attacks depend on:
| Service | Details |
| :------ | :------ |
| **Penetration Testing & Security Testing** | Applications, APIs, infrastructure, and systems. Written authorisation, agreed scope, named emergency stop. Reports describe what worked — never which person fell for it. |
| **Social Engineering Defense** | Phishing, vishing, SMiShing, callback phishing, impersonation, adversarial simulation, and AI/deepfake social engineering — then the Human Firewall Program. |
| **Cybersecurity Training** | Practical awareness training so people can recognise and respond to real attacks. |
| **Account & Social Media Recovery** | Support for compromised or inaccessible accounts, plus exposure removal. Best-effort — we do not promise guaranteed outcomes. |
| **Human Risk & Advisory** | Identify where people are vulnerable to social engineering. Security advisory and vCISO support where needed. |
| **Executive & VIP Protection** | Digital protection for executives and families — often the softer path into an organisation. |

Followed by the **Human Firewall Program** that strengthens human defences over time.
Also available: threat intelligence, dark web monitoring and data removal, incident response, and deepfake verification.

### Cybersecurity Training
<div align="center">

Practical security awareness and social engineering training so people can recognise and respond to real attacks.
<br />

### Account & Social Media Recovery
### Free capacity, every month

Support for compromised or inaccessible online accounts and social media accounts, plus exposure removal. Recovery is best-effort — we do not promise guaranteed outcomes.
We reserve capacity for schools, clinics, charities, and community groups.
Being underfunded should not mean being undefended.
**If that is you, write to us and say so.**

---
</div>

---

<div align="center">

## Why We Build

AI is changing how software is built. It is also changing how attacks are created, automated, and scaled.
AI is changing how software is built.
It is also changing how attacks are created, automated, and scaled.

AwareXone builds security tools and services around that change.

We want the AI era to be safer for the people building it and the people using it.
**We want the AI era to be safer for the people building it and the people using it.**

</div>

---

<div align="center">

## Who We Build For

</div>

<br />

| Who | Why |
| :-- | :-- |
| **Developers** | Secure AI-built and modern applications before they ship |
| **Security researchers** | Find, validate, and report real vulnerabilities |
| **Organizations** | Protect applications, people, accounts, and digital assets |
| **Individuals** | Protect online accounts and reduce digital risk |
| **AI builders** | Build safer AI applications and agents |

---

<div align="center">

## Website & Contact
## Explore AwareXone

**Explore AwareXone →** [www.awarexone.com](https://www.awarexone.com)
**[www.awarexone.com](https://www.awarexone.com)**

[Services](https://www.awarexone.com/services) · [Open source](https://www.awarexone.com/open-source) · [Research](https://www.awarexone.com/blog)

<br />

**[awarexone@gmail.com](mailto:awarexone@gmail.com)** — engagements, open source, disclosure
**[hello@awarexone.com](mailto:hello@awarexone.com)** — general contact

<br />

[GitHub](https://github.com/Awarexone) · [X](https://x.com/awarexone)

</div>

---

## About AwareXone
<div align="center">

## About

AwareXone builds open-source security tools and provides cybersecurity services for the AI era.

Our work spans AI security, application security, offensive security, social engineering defense, human risk, and digital protection.
AI security · Application security · Offensive security · Social engineering defense · Human risk · Digital protection

</div>

---

## Contributing
<div align="center">

### Contributing

Issues and pull requests welcome on the public repositories.
Security disclosures → **[awarexone@gmail.com](mailto:awarexone@gmail.com)**

Open-source contributions are welcome on the public repositories above. Prefer issues and pull requests on the relevant project. For security disclosures, email **[awarexone@gmail.com](mailto:awarexone@gmail.com)**.
### Responsible Use

## Responsible Use
Use offensive tools only with explicit authorisation and agreed scope.

Offensive tools and techniques must only be used with explicit authorisation and within agreed scope. Do not use AwareXone projects or services to harm systems, people, or accounts you do not own or have permission to test.
### License

## License
Each repository carries its own license. See that project's `LICENSE` file.

Each open-source repository carries its own license. See the `LICENSE` file in that project.
</div>