Skip to content
View ExploitCraft's full-sized avatar
🎯
Focusing
🎯
Focusing

Organizations

@HackerInc

Block or report ExploitCraft

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ExploitCraft/README.md

Hey, I'm ExploitCraft πŸ‘Ύ

Typing SVG

Security Tool Builder Β· Self-Taught Developer Β· Bangladesh

Website Fiverr PyPI Twitter YouTube Email

TryHackMe


πŸ’« About Me

I'm ExploitCraft β€” a 13-year-old self-taught developer from Bangladesh building open-source security tools. Started from zero, learned by doing, and shipped real projects with proper tests, documentation, and CI/CD.

  • πŸ”­ Currently building the ExploitCraft security toolkit
  • 🌱 Learning penetration testing, network security, and Next.js
  • 🎯 2026 Goal: grow ExploitCraft into a recognized open-source security org
  • ⚑ Fun fact: Googled my way to shipping 533-test Python frameworks at 13

πŸ› οΈ Projects

πŸ” ReconNinja β€” v7.1.0

21-phase automated recon framework β€” subdomain enum, port scanning (RustScan/Masscan/Nmap), web discovery (httpx/Nikto/Nuclei), CVE lookup, AI threat analysis, plugin system, resume support, dark-mode HTML reports. 533 tests Β· Python Β· MIT

🐾 VaultHound β€” v1.0.0

Secret & credential scanner β€” URL mode, directory mode, git history mode. 43 detection patterns covering AWS, GCP, GitHub, Stripe, OpenAI, Anthropic, Slack, private keys, JWT, DB strings. Entropy-based false positive filtering. Python Β· MIT

πŸ” envleaks β€” v1.1.0

Secret & credential scanner for codebases, git history, and Docker images. 60+ detection patterns covering AWS, GitHub, OpenAI, Anthropic, Stripe, Slack, private keys, JWT, DB strings. SARIF output for GitHub Advanced Security. CI/CD pipeline mode. Python Β· MIT

πŸ“‘ wifi-passview β€” v1.1.1

Cross-platform CLI to dump saved WiFi credentials in one command. Linux (NetworkManager, wpa_supplicant, iwd), Windows (netsh), macOS (Keychain). Terminal, JSON, and CSV output. Redact mode for safe screenshots. Python Β· MIT

🎯 gitdork β€” v1.1.0

Google, Shodan, and GitHub dork generator. Feed it a repo URL or domain β€” get ready-to-use dork queries targeting exposed secrets, sensitive files, open directories, and misconfigs. Built for pentesters and bug bounty hunters. Python Β· MIT


πŸ’» Tech Stack

Python TypeScript JavaScript PHP HTML5 CSS3 PowerShell Markdown Next JS Flask Docker Git GitHub GitLab CI Nginx Apache MariaDB NPM TOR Home Assistant Jellyfin Affinity Designer Affinity Photo Epic Games


πŸ“Š GitHub Stats

GitHub Stats GitHub Streak Top Languages


πŸ† Trophies


✍️ Dev Quote


⚠️ All tools are for authorized security testing only.

Pinned Loading

  1. ReconNinja ReconNinja Public

    ⚑ ReconNinja v7.1.0 β€” 38-phase recon framework for pentesters & bug bounty hunters. Subdomain enum β†’ port scan β†’ web recon β†’ WAF/CORS/JS/cloud bucket detection β†’ GitHub OSINT β†’ CVE lookup β†’ AI thre…

    Python 15 2

  2. VaultHound VaultHound Public

    VaultHound β€” A fast, pattern-based secret and credential scanner. Scans local directories, Git history, and URLs for leaked API keys, tokens, passwords, and private keys across 40+ patterns (AWS, G…

    Python 15 1

  3. fastfetch-config fastfetch-config Public

    Arch Linux fastfetch config with Kitty image protocol, Nerd Font icons, and a clean box-bordered layout.

    12

  4. envleaks envleaks Public

    Scan codebases, git history, and Docker images for accidentally exposed secrets

    Python 15 1

  5. wifi-passview wifi-passview Public

    Cross-platform CLI to dump saved WiFi credentials β€” Linux, Windows, macOS

    Python 16 1

  6. gitdork gitdork Public

    Google, Shodan, and GitHub dork generator for pentesters and bug bounty hunters

    Python 14 1