Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

๐Ÿ” [Project] I built a Telegram bot for automated pentesting & recon โ€” looking for feedback!

published on 2025-11-01 03:16:59 UTC by /u/Swimming-Design-1412
Content:

๐Ÿ” [Project] I built a Telegram bot for automated pentesting & recon โ€” looking for feedback!

Hey everyone ๐Ÿ‘‹

For the past few months Iโ€™ve been working on a side project called WebSecAnalyst_Bot, a Telegram-based pentest assistant that automates common reconnaissance and vulnerability checks directly from chat.

The idea came from my own bug bounty workflow โ€” I wanted a quick, portable way to run small recon tasks (like subdomain or port scans) without setting up Burp, Nmap, or a full VPS.

Now the MVP is complete, and Iโ€™m opening it up for feedback from the community (especially bug bounty hunters, pentesters, and websec researchers).

โš™๏ธ What the bot currently does

  • ๐ŸŒ Subdomain enumeration
  • ๐Ÿงฉ Directory brute-force (common paths)
  • ๐Ÿ”Œ Port scanning (non-intrusive)
  • ๐Ÿ”’ SSL & security header analysis
  • ๐Ÿ›ก๏ธ WAF and CMS detection
  • ๐Ÿ”— Broken link & SEO audits
  • ๐Ÿ’ฐ Credit system + free daily scan (Stripe integration)

All scans are performed through controlled, rate-limited API calls โ€” nothing destructive or intrusive.

๐Ÿงช Iโ€™m mainly looking for feedback on

  • Accuracy of recon results compared to your usual tools (Amass, Nmap, etc.)
  • Response structure โ€” is the Telegram output clear and actionable?
  • Feature ideas: API fuzzing? tech fingerprinting? passive DNS?
  • Performance (especially latency and concurrency issues)

๐Ÿ’Ž For testers

Everyone who participates and sends useful feedback will get free credits and early access to new features (like async scans and vulnerability checks).

๐Ÿš€ Try it out

You can test it directly on Telegram here:
๐Ÿ‘‰ Telegram Web

Commands available:
/subdomains, /ssl, /dirs, /portscan, /cms, /waf, /headers, /brokenlinks

โš ๏ธ Ethical note

Please use the bot only on domains you own or have permission to test.
This is strictly for educational, security, and bug bounty purposes โ€” no illegal use tolerated.

Any kind of feedback (technical, UX, or even critique) is super appreciated ๐Ÿ™
This project is open for honest reviews and suggestions โ€” Iโ€™ll gladly iterate based on what the community says.

Thanks for reading, and I hope some of you find it useful or interesting to test! ๐Ÿš€

#BugBounty #EthicalHacking #CyberSecurity #Pentesting #TelegramTools #Recon #Automation #WebSecAnalyst_Bot

submitted by /u/Swimming-Design-1412
[link] [comments]
Article: ๐Ÿ” [Project] I built a Telegram bot for automated pentesting & recon โ€” looking for feedback! - published about 6 hours ago.

https://www.reddit.com/r/netsec/comments/1oldt0n/project_i_built_a_telegram_bot_for_automated/   
Published: 2025 11 01 03:16:59
Received: 2025 11 01 03:19:20
Feed: /r/netsec - Information Security News and Discussion
Source: /r/netsec - Information Security News and Discussion
Category: Cyber Security
Topic: Cyber Security
Views: 5

Custom HTML Block

Click to Open Code Editor