Hey everyone ๐
For the past few months Iโve been working on a side project called WebSecAnalyst_Bot, a Telegram-based pentest assistant that automates common reconnaissance and vulnerability checks directly from chat.
The idea came from my own bug bounty workflow โ I wanted a quick, portable way to run small recon tasks (like subdomain or port scans) without setting up Burp, Nmap, or a full VPS.
Now the MVP is complete, and Iโm opening it up for feedback from the community (especially bug bounty hunters, pentesters, and websec researchers).
All scans are performed through controlled, rate-limited API calls โ nothing destructive or intrusive.
Everyone who participates and sends useful feedback will get free credits and early access to new features (like async scans and vulnerability checks).
You can test it directly on Telegram here:
๐ Telegram Web
Commands available:
/subdomains, /ssl, /dirs, /portscan, /cms, /waf, /headers, /brokenlinks
Please use the bot only on domains you own or have permission to test.
This is strictly for educational, security, and bug bounty purposes โ no illegal use tolerated.
Any kind of feedback (technical, UX, or even critique) is super appreciated ๐
This project is open for honest reviews and suggestions โ Iโll gladly iterate based on what the community says.
Thanks for reading, and I hope some of you find it useful or interesting to test! ๐
#BugBounty #EthicalHacking #CyberSecurity #Pentesting #TelegramTools #Recon #Automation #WebSecAnalyst_Bot
Click to Open Code Editor