Skip to content
View whoiskay404's full-sized avatar
💭
kaysociety ethical hacker
💭
kaysociety ethical hacker

Block or report whoiskay404

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
whoiskay404/README.md

KARABO KOSI

whoiskay — Cybersecurity Engineer • Penetration Tester • Web Developer

Portfolio GitHub Email

⚡ BOOT SEQUENCE

Initializing whoiskay profile...
[██████████████████████] 100%

Operator Loaded.
Recon Modules Loaded.
Exploit Chains Ready.
Target Acquisition Enabled.
---

👾 WHOAMI

name: Karabo Kosi
alias: whoiskay
country: Botswana 🇧🇼
specialization:
  - Web Application Security
  - API Security Testing
  - Network Security
  - Bug Bounty Hunting
  - Recon Automation
certifications:
  - CompTIA Security+
  - CompTIA A+
  - CoreVex Range Cyber
status: Hunting for impact.

🎯 About Me

🎓 Student & Developer

BSc Cybersecurity & Digital forensics
📍 Gaborone, Botswana 🇧🇼
💡 Build, Break and Secure to deliver quality scalable product solutions

🚀 Areas of Intrests

🎯 Penetration Testing
🔨 Web Development
🌱 Cybersecurity Engineering
💼 Bug Bounty Hunting

🛡️ Cybersecurity Arsenal

🔍 Recon & Enumeration


subfinder • amass • assetfinder • httpx • katana • gau • waybackurls

⚔️ Web Exploitation


Burp Suite • SQLmap • Nuclei • ffuf • XSStrike • Dalfox • Commix

🌐 Network Security


Nmap • Wireshark • Netcat • Bettercap • Responder • Aircrack-ng

🛠️ Reverse Engineering


Ghidra • Radare2 • Binary Ninja • Apktool • Frida • IDA Free

☠️ Red Team & Pentesting

Metasploit • Empire • Sliver • Havoc • CrackMapExec • BloodHound • Impacket

🧠 Scripting & Automation


Custom Recon Tools • Automation Scripts • API Testing • CI/CD Security

🐉 Kali Linux Toolkit

Burp Suite • Nuclei • Gobuster • Dirsearch • Hydra • John The Ripper • Hashcat • Nikto • WPScan

📂 Reporting & Collaboration


Markdown • HTML Reports • JSON Reports • Bug Bounty Dashboards

🚀 Featured Projects

🔐 Web Dev

Development of Websites




🛡️ Cybersecurity Tools

Web and Network Advanced Testing Tools




🤖 Automation

Developing and automating workflows





⚡ Tech Arsenal


☠️ CUSTOM OFFENSIVE TOOLS

🔍 Recon_Security

+ Subdomain Enumeration
+ Live Host Validation
+ JS Secret Discovery
+ XSS Reflection Detection
+ Endpoint Mapping
+ HTML Reports

⚔️ Misconfig_Security

+ Passive + Active Recon
+ Security Header Analysis
+ TLS Inspection
+ Cookie Security Checks
+ Metadata Discovery
+ Risk Prioritization

🎯 LIVE TARGET MATRIX


📊 GitHub Analytics

Featured Work

Recon_Security

A security reconnaissance project focused on turning repetitive discovery work into an organized workflow.

Capabilities

  • Subdomain enumeration
  • Live-host validation
  • JavaScript secret discovery
  • XSS reflection detection
  • Endpoint mapping
  • HTML reporting

Repository:
https://github.com/whoiskay404/Recon_Security_v2


priv_esc

A collection of privilege-escalation research and practical security work.

Repository:
https://github.com/whoiskay404/priv_esc


Kay Bug Bounty Hunter

A security-focused toolkit for identifying common web and network misconfigurations, with an emphasis on repeatable testing and automation.

Repository:
https://github.com/kaysociety/kaybugbountyhunter


Web Development

Security is only one side of what I build. I also develop websites and web applications with a focus on clean interfaces, practical functionality, and maintainable implementations.

Selected Projects



🧠 CURRENT OPERATIONS

[+] Hunting bug bounty targets
[+] Building next-gen recon automation
[+] Deep-diving API attack surfaces
[+] Practicing advanced web exploitation

🏆 CERTIFIED OPERATOR


🕶 ATTACK SURFACE


🌍 SECURE CHANNELS

Email


🔥 QUOTE OF OPERATOR

+ "Every bug is a hidden door. My job is to find it."

Pinned Loading

  1. GirlsInIcT-website-demo GirlsInIcT-website-demo Public

    ICT Website

    HTML 3

  2. LightRecon_security LightRecon_security Public

    WEB APPLICATION RECON

    Python 2

  3. Misconfig_Security_v2 Misconfig_Security_v2 Public

    A lightweight, fast reconnaissance and web hygiene scanner focused on safe, controlled checks rather than noisy scanning. It analyzes security headers, cookie flags, CORS policy, HTTP methods, TLS …

    Python 2

  4. priv_esc priv_esc Public

    Linux local privilege-escalation research toolkit. The project consolidates a collection of legacy Linux privilege-escalation exploits and supporting scripts, with an automated runner capable of f…

    Shell 2

  5. Recon_Security Recon_Security Public

    ADVANCED INJECTION POINT AND VULNERABILITY SCANNER

    Python 2

  6. Recon_Security_v2 Recon_Security_v2 Public

    A fast, multi-threaded reconnaissance framework built for bug bounty hunters and penetration testers. It automates the full recon pipeline — subdomain discovery, live host and port detection, URL/J…

    Python 2