Burp Suite extension (Java, Montoya API) that parses Server-Sent Events — including SignalR streams delimited by the record separator (0x1E). Adds an SSE Parser tab with an event table, full event detail, and logs, for traffic Burp otherwise leaves as an opaque stream.
visitor@0xll.sh:~$ whoami --verbose
0xll
penetration tester · red team operator · bug bounty
I break into things that are supposed to be secure — with a signed SOW and rules of engagement — then write it up so it gets fixed. Focus on Active Directory, C2 & evasion, and external attack surface.
Computes the MurmurHash3 of a favicon — from a URL or a local file — and pivots it through Shodan to find every host serving the same asset. Optional ProjectDiscovery uncover fallback, with JSON/CSV export for piping into the rest of a recon chain.
External attack-surface recon orchestrator for authorized pentests. Chains passive sources (crt.sh, OTX, Anubis, Wayback) with per-IP Shodan/IPinfo enrichment, HTTP probing, subdomain-takeover leads, and Cloudflare origin-IP discovery, with optional ProjectDiscovery backends. Produces a report-ready Markdown/HTML deliverable plus a live-host list for nuclei/httpx handoff.
visitor@0xll.sh:~$ cat contact.txt
For coordinated disclosure or engagement inquiries, PGP preferred.
$ logout process exited with code 0 · © 2026 0xll