Skip to content
@Awarexone

AwareXone

Open-source security tools and research for a safer digital world.
AwareXone — social engineering defence. Vishing, phishing, SMiShing, callback phishing, adversarial simulation, deepfake social engineering.

Attackers hack people, not firewalls.

AwareXone is a social engineering defence and human risk consultancy. We run the attacks your staff will really face — the phone call, the invoice, the cloned voice, the service desk reset — and then rebuild the judgement those attacks depend on.

Every offensive engagement runs on written authorisation, an agreed scope and a named emergency stop contact. Reports describe what worked, never which individual fell for it.

Based in Malaysia. Working worldwide.


Open source

Everything we build for the open source program is permissively licensed and self-hostable. No telemetry, no gated tier, no upgrade path that quietly becomes the product.

Project What it is
Agentic-Bug-Hunter An agentic reconnaissance and vulnerability discovery toolkit for bug bounty work. Built to be useful on a free tier rather than gated behind one. Stars
public-skills-builder Turns published HackerOne reports and GitHub write-ups into working agent skills across eighteen vulnerability classes. Nothing confidential goes in or out. Stars
web3-bug-bounty-hunting-ai-skills A smart contract security skill library built from 2,749 Immunefi reports and 681 DeFiHack reproductions. The patterns that actually pay out, not the textbook list. Stars

Alongside the tools, the program publishes the pretexts we see in engagements — anonymised — so defenders learn about a technique before it reaches them rather than after.

What we do

Social engineering and training — the people attackers actually call. Our main engagement: vishing, phishing, SMiShing, callback phishing, adversarial simulation and AI-driven deepfake social engineering, then the Human Firewall Program that rebuilds the judgement behind them.

Cybersecurity services — everything behind the person who was called. Penetration testing, threat intelligence, dark web monitoring and data removal, incident response and deepfake verification, security advisory and vCISO.

Account and executive recovery — when it is already personal. Account recovery, exposure removal, and executive and VIP digital protection. Families are covered as standard, because that is usually the softer route to an executive.

Free capacity, every month

We reserve capacity every month for schools, clinics, charities and community groups. Being underfunded should not mean being undefended. If that is you, write to us and say so.

Contact

awarexone@gmail.com — engagements, open source, disclosure

www.awarexone.com · Services · Open source · Research

Pinned Loading

  1. Agentic-Bug-Hunter Agentic-Bug-Hunter Public

    AI-powered bug bounty hunting toolkit that works with or without subscription.

    Python 4.5k 803

  2. public-skills-builder public-skills-builder Public

    Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed

    Python 224 50

  3. web3-bug-bounty-hunting-ai-skills web3-bug-bounty-hunting-ai-skills Public

    18 Claude Code skill files for smart contract security — built from 2,749 Immunefi reports, 681 DeFiHack reproductions, and real hunt experience

    130 35

Repositories

Showing 4 of 4 repositories

Top languages

Loading…

Most used topics

Loading…