Building open-source security infrastructure for the AI era.
We build security tools and services that help developers, security researchers, organizations, and individuals find vulnerabilities, prevent attacks, and protect their digital assets.
Website · Open Source · Services · GitHub · X
Security tools for AI-built applications, AI agents, APIs, source code, and modern software — so issues are found before they ship.
Vulnerability discovery, penetration testing, bug bounty research, and application security testing — against real systems, with written authorisation and agreed scope.
Defense and training around phishing, vishing, SMiShing, callback phishing, impersonation, and AI/deepfake social engineering — then rebuilding the judgement those attacks depend on.
Account and social media recovery support, exposure removal, and executive / VIP digital protection. Families are covered as standard. We do not guarantee recovery outcomes.
Based in Malaysia. Working worldwide.
Our pinned open-source projects on GitHub:
| Project | Description | |
|---|---|---|
| Agentic-Bug-Hunter | AI-powered bug bounty hunting toolkit that works with or without subscription. | |
| public-skills-builder | Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed. | |
| web3-bug-bounty-hunting-ai-skills | 18 Claude Code skill files for smart contract security — built from 2,749 Immunefi reports, 681 DeFiHack reproductions, and real hunt experience. | |
| AXguard | Open-source AI security tool to scan and fix vulnerabilities in your vibe-coded apps before you ship. AXguard by AwareXone. |
AwareXone also works directly with organizations and individuals.
We run the attacks your staff will really face — the phone call, the invoice, the cloned voice, the service desk reset — then rebuild the judgement those attacks depend on:
Followed by the Human Firewall Program that strengthens human defences over time.
Practical security awareness and social engineering training so people can recognise and respond to real attacks.
Support for compromised or inaccessible online accounts and social media accounts, plus exposure removal. Recovery is best-effort — we do not promise guaranteed outcomes.
AI is changing how software is built. It is also changing how attacks are created, automated, and scaled.
AwareXone builds security tools and services around that change.
We want the AI era to be safer for the people building it and the people using it.
Explore AwareXone → www.awarexone.com
Services · Open source · Research
[email protected] — engagements, open source, disclosure
[email protected] — general contact
AwareXone builds open-source security tools and provides cybersecurity services for the AI era.
Our work spans AI security, application security, offensive security, social engineering defense, human risk, and digital protection.
Open-source contributions are welcome on the public repositories above. Prefer issues and pull requests on the relevant project. For security disclosures, email [email protected].
Offensive tools and techniques must only be used with explicit authorisation and within agreed scope. Do not use AwareXone projects or services to harm systems, people, or accounts you do not own or have permission to test.
Each open-source repository carries its own license. See the LICENSE file in that project.