
MAX
@MAXdeg0 • 12,525 subscribers
AI • Agents • Open Source tools DM open for collab ✉️
Shorts
Videos

THIS IS F**KING DANGEROUS SOME COMPANIES ARE LEAVING WAY TOO MUCH EXPOSED I found 3 OSINT tools that can uncover a ridiculous amount of information from the outside. LEAKIX -> Give it a domain and it can surface publicly exposed services and databases connected to that infrastructure. ARGUS -> Runs 135+ recon and security checks against a website to build a much broader picture of its external footprint. GITGRABER -> Monitors GitHub for accidentally exposed secrets like API keys, passwords, and sensitive information —> with Telegram alerts when something is found. Different tools. Same idea: find what shouldn’t be publicly visible. If you’re learning OSINT, bug bounty, or pentesting, these are worth knowing. BOOKMARK it before someone take it down LINK’S BELOW
MAX239,145 views • 20 days ago

THIS IS F**KING DANGEROUS FOUND 3 TOOLS THAT FEELS ILLEGAL TO USE and they are all FREE to use HACKING TOOL → 215+ security tools packed into one platform, including 26 OSINT tools. DARK WEB SEARCH → Search through indexed dark-web content and find information you probably wouldn’t see on Google. EMAIL OSINT → Enter an email and uncover accounts, names, photos, and exposed data connected to it. The amount of info this tools can connect is crazy BOOKMARK this before someone take it down LINK’S BELOW
MAX54,658 views • 8 days ago

THIS IS F**KING DANGEROUS THE INTERNET IS LEAKING WAY MORE INFORMATION THAN MOST PEOPLE REALIZE. I FOUND 3 OSINT TOOLS THAT CAN HELP YOU DIG DEEPER INTO WHAT’S ALREADY PUBLIC. SHODAN IMAGES can surface screenshots from internet-connected devices that are publicly exposed. GHOST-TRACK pulls together information from IP addresses, usernames, and phone numbers to help connect the dots. Then there’s FLOWSINT — a visual OSINT workspace that lets you map relationships between people, websites, accounts, and other data points. The scary part? You don’t need to be inside the network to start finding useful information. You just need to know where to look. BOOKMARK this before someone take it down LINKS BELOW
MAX48,979 views • 14 days ago

THIS IS F**KING DANGEROUS SOMEONE JUST TURNED CLAUDE INTO AN AUTONOMOUS PENTESTER. HexStrike AI connects an LLM to 150+ professional cybersecurity tools through MCP. You get: → 12 specialized AI agents → 150+ security tools → Network & web security testing → Automated pentesting workflows → Local execution on Kali Linux The wild part? Claude autonomously generated a SQL injection payload, ran the test, and solved a PortSwigger lab. AI + real security tooling is getting serious. REPO BELOW
MAX62,640 views • 1 month ago

WHOEVER BUILT THIS HAS ZERO FEAR. SOMEONE CONNECTED 200 GROK BOTS INTO ONE AUTONOMOUS TRADING SYSTEM. -> One bot researches. -> Another tracks markets. -> Another analyzes sentiment. -> Another watches on-chain activity. But instead of leaving 200 separate outputs everywhere, they’re all connected through a CONTEXT GRAPH that turns the swarm’s information into one coherent picture. 200 bots. ONE TRADING BRAIN.
MAX61,804 views • 1 month ago

THIS IS F**CKING DANGEROUS I WENT DOWN AN OSINT RABBIT HOLE AND FOUND 3 TOOLS I WISH I KNEW ABOUT SOONER The first one is GRAYHAT WARFARE. It searches exposed cloud storage for files people accidentally left public. Then there’s KASPERSKY CYBERTHREAT LIVE MAP. You can watch cyber threats moving across the internet in real time. And the third one caught my attention: GEOAXIS Give it a photo. No GPS. No metadata. It analyzes the image and tries to figure out where it was taken. Three completely different tools, but they all exploit the same idea: People leave an insane amount of information behind without realizing it. You don’t always need to “hack” anything. Sometimes you just need to know where to look. BOOKMARK this before someone take it down LINK’S BELOW
MAX41,313 views • 23 days ago

WHY ARE AI DEVELOPERS STILL PAYING FOR 5+ DIFFERENT APIs? GPT -> Claude -> Gemini -> DeepSeek -> Grok. Different providers. Different keys. Different integrations. And a growing API bill. DIT ai changes that. → One API gives you access to 50+ leading AI models with a single key. → Lower costs requests are routed across 160+ providers to find competitive real time pricing, with typical savings of 30–70% depending on the model and route. → Keep your stack — DIT ai is OpenAI compatible. Change your base URL + API key instead of rebuilding your entire integration. → Automatic failover — if an upstream provider fails before the response begins, DIT ai automatically reroutes to another qualified provider. For AI agents, SaaS products, startups, and anyone pushing serious API volume, this could make managing AI infrastructure a lot simpler. Same models. One key. Lower bill. LINK BELOW TO TRY IT OUT
MAX45,561 views • 29 days ago

THIS IS F**KING DANGEROUS FOUND 3 ETHICAL HACKING TOOLS THAT FEELS ILLEGAL TO USE And it all open source and free to use If you’re learning pentesting, these belong in your toolkit: → Arsenal-ng — a huge terminal library of pentesting commands for recon, scanning, exploitation and more. → Pentest-copilot — an AI powered assistant that helps automate exploitation workflows and chain attack steps. → Ligolo-ng — lets you tunnel and pivot through a compromised machine to reach systems inside a private network. Different jobs. One goal: make pentesting faster and more efficient. BOOKMARK this before someone take it down REPO’S BELOW
MAX38,815 views • 25 days ago

THIS IS F**KING DANGEROUS THESE OSINT TOOLS CAN DIG UP WAY MORE THAN YOU’D EXPECT I FOUND 3 TOOLS THAT SHOW JUST HOW MUCH INFORMATION CAN BE CONNECTED FROM PUBLIC DATA. MAIGRET searches 3,000+ sites to uncover accounts connected to a username or email. TRAPE can help analyze visitor and browser data during authorized security testing. Then BLACKBIRD uses AI-powered analysis to connect username data and generate deeper insights from the information it finds. The interesting part isn’t just finding the data. It’s what AI can do once all that data is connected. OSINT + AI IS A CRAZY COMBINATION. BOOKMARK this before someone take it down REPO’S BELOW
MAX16,728 views • 11 days ago

WHOEVER BUILT THIS GROK BOT TRADING SWARM KNEW EXACTLY WHAT THEY WERE DOING 300 AGENTS DON’T NEED TO RUN 24/7. They just need to show up, analyze the market, finish the job, and disappear. Grok bot makes the decision. Kimi spins up the swarm. Then the agents attack the market from different angles: 300 agents → market data + news + on-chain signals → 140+ connected sources → contradictions surfaced → one consolidated trading signal One agent finds a setup. Another challenges it. A third checks the underlying data. Another runs the risk analysis. The system keeps the conflicting signals instead of blindly trusting the first answer. Then everything gets merged back into one trading decision. That’s the part people miss. The 300 agents aren’t the breakthrough. The coordination is. This is what a Grok powered AI trading desk starts looking like. FULL GUIDE ON HOW TO SET IT UP BELOW
MAX38,807 views • 1 month ago

THIS IS F**KING DANGEROUS FOUND AN AI RED TEAM THAT NEEDS ZERO HUMAN INPUT PentAGI. Scanner —> Exploiter —> Reporter —> three agents, working as a swarm, sharing results in real time. One does recon, another finds and runs the actual exploits, a third writes the professional vulnerability report at the end. FULLY AUTONOMOUS —> plans its own steps, executes through terminal, browser, and code editor, monitors its own progress. Runs entirely inside sandboxed Docker, integrated with 20+ real security tools (Nmap, Metasploit, SQLmap, and more). It has over 22k STARS on GitHub MIT licensed, self hostable —> free if you run it on local models, cloud LLM costs only if you plug in OpenAI or Claude. The tradeoff nobody skips past: this drops the cost of serious security testing for companies who couldn't afford it before and puts the same capability in everyone's hands. Cybersecurity is genuinely becoming AI vs AI. Authorized security testing only. Using this on systems you don't own is illegal. REPO BELOW
MAX37,737 views • 1 month ago

THIS IS F**KING INSANE Found something genuinely comprehensive: ANTHROPIC CYBERSECURITY SKILLS 817 production grade security skills for AI agents, open source. 29 security domains —>cloud security—>threat hunting—>network security—>incident response—>malware analysis, red teaming, and more all mapped against real frameworks: MITRE ATT&CK v17.1, NIST CSF 2.0, OWASP, MITRE Fight Fraud Framework, CIS Controls, and more. Each skill ships with full YAML frontmatter, references the exact framework techniques it covers, and works across Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, and Gemini CLI. Quick start is a one line clone. Free, open source, actively maintained. Repo below
MAX46,126 views • 1 month ago

WHOEVER BUILT THIS WAS TIRED OF INSTALLING 50 DIFFERENT HACKING TOOLS Someone turned 183+ penetration testing and OSINT tools into ONE command line toolkit. —> Recon. —> Vulnerability scanning. —> Web app testing. —> iOS security. —> OSINT. All sitting behind a single CLI menu. Instead of spending hours installing tools, configuring dependencies and jumping between terminals, you can manage the whole stack from one place. And because it’s open source, you can actually inspect it, modify it and build your own workflows around it. Cybersecurity students are going to have a field day with this. Just remember: use it on systems you own or have explicit permission to test. This is basically a Swiss Army knife for security researchers. REPO BELOW
MAX27,121 views • 1 month ago

Bloomberg is now comparing Kimi K3 to BYD Chinese tech that's as good, cheaper, and something the US might try to block. Bloomberg's global tech editor Peter Ellstrom on the moment: this "outstrips most of the frontier models" except Anthropic and OpenAI's top two. He says it's forcing pricing pressure right as OpenAI and Anthropic chase trillion dollar IPO valuations. There's already talk in Washington about restricting Chinese models but Ellstrom's warning: block them, and you don't just hurt the frontier labs, you hurt every American business that isn't one. This isn't just another DeepSeek moment. Bloomberg thinks it's bigger.
MAX37,215 views • 2 months ago

🚨 SOMEONE JUST TURNED AN LLM INTO AN AUTONOMOUS RED TEAM Cyberstrike is an open source AI security agent built to automate penetration testing from your terminal. Plug in your Claude, GPT, or other LLM subscription and you get: → 13+ specialized security agents → 7,600+ security skills → 120+ OWASP test cases → 150+ AI providers → 5,300+ models → 56+ built in tools → 176+ MCP tools Instead of one AI trying to do everything, it splits security work across specialized agents. This is where AI powered pentesting gets seriously interesting. Use it only on systems you own or have explicit permission to test. REPO BELOW
MAX17,029 views • 1 month ago

THIS IS F**KING INSANE FOUND 3 TOOLS THAT WILL SAVE YOU RIDICULOUS AMOUNT OF TIME IF YOU’RE DOING RECON And it all open source and free to use → Photon — scrapes a target and maps links, subdomains, files, and exposed information. → APIs for OSINT — a massive collection of free OSINT APIs organized across categories like geolocation, faces, domains, and more. → ReconFTW — automates the recon process by chaining multiple tools together, mapping a target’s attack surface and generating a report. The crazy part? You can go from manually hunting through a target… to having an entire recon workflow running with a single command. If you’re learning cybersecurity, bug bounty, or OSINT BOOKMARK these before someone take it down REPO BELOW
MAX12,255 views • 26 days ago

THIS IS WHAT AI PENTESTING SHOULD LOOK LIKE IN 2026 Someone built Shannon, an open source AI pentesting tool that doesn’t just scan your app from the outside. It reads the source code. Then it uses AI to map potential attack paths, identify vulnerabilities, and test the application before you ship it. The workflow is basically: → point Shannon at your code → connect your Claude API → let it analyze the application → get the findings in a dashboard Instead of waiting for a security team to manually hunt through every part of your codebase, you can have an AI security researcher working through it automatically. And because it’s white-box, it can see things traditional scanners can’t. This is where AI + cybersecurity gets REALLY interesting. Just use it on systems you own or have explicit permission to test. REPO BELOW
MAX13,228 views • 1 month ago

Someone built a laser turret that autonomously tracks and pops balloons for a school deadline, on an ESP32. The real story is the debugging: TinyML on the ESP32-CAM alone maxed out at 2fps. Switching to YOLO on a laptop helped but was still too slow. Baud rate bottleneck killed it again fixed by streaming over Ethernet instead, which finally gave smooth, precise tracking. Same $8 hardware philosophy as the article below local AI doesn't need a $3,000 rig, it needs the right bottleneck fixed.
MAX19,727 views • 2 months ago
No more content to load