Initializing whoiskay profile...
[██████████████████████] 100%
Operator Loaded.
Recon Modules Loaded.
Exploit Chains Ready.
Target Acquisition Enabled.name: Karabo Kosi
alias: whoiskay
country: Botswana 🇧🇼
specialization:
- Web Application Security
- API Security Testing
- Network Security
- Bug Bounty Hunting
- Recon Automation
certifications:
- CompTIA Security+
- CompTIA A+
- CoreVex Range Cyber
status: Hunting for impact.
Metasploit • Empire • Sliver • Havoc • CrackMapExec • BloodHound • Impacket
Custom Recon Tools • Automation Scripts • API Testing • CI/CD Security
Burp Suite • Nuclei • Gobuster • Dirsearch • Hydra • John The Ripper • Hashcat • Nikto • WPScan
Markdown • HTML Reports • JSON Reports • Bug Bounty Dashboards
+ Subdomain Enumeration
+ Live Host Validation
+ JS Secret Discovery
+ XSS Reflection Detection
+ Endpoint Mapping
+ HTML Reports+ Passive + Active Recon
+ Security Header Analysis
+ TLS Inspection
+ Cookie Security Checks
+ Metadata Discovery
+ Risk PrioritizationA security reconnaissance project focused on turning repetitive discovery work into an organized workflow.
Capabilities
- Subdomain enumeration
- Live-host validation
- JavaScript secret discovery
- XSS reflection detection
- Endpoint mapping
- HTML reporting
Repository:
https://github.com/whoiskay404/Recon_Security_v2
A collection of privilege-escalation research and practical security work.
Repository:
https://github.com/whoiskay404/priv_esc
A security-focused toolkit for identifying common web and network misconfigurations, with an emphasis on repeatable testing and automation.
Repository:
https://github.com/kaysociety/kaybugbountyhunter
Security is only one side of what I build. I also develop websites and web applications with a focus on clean interfaces, practical functionality, and maintainable implementations.
- Portfolio: https://whoiskay.vercel.app
- CyberUnit: (Information Is Private)
- CrocTown: https://croctown.vercel.app
- ClotheStore: https://clothestore-iota.vercel.app
[+] Hunting bug bounty targets
[+] Building next-gen recon automation
[+] Deep-diving API attack surfaces
[+] Practicing advanced web exploitation+ "Every bug is a hidden door. My job is to find it."











