Gunnar Andrews Profile Banner
Gunnar Andrews Profile
Gunnar Andrews

@G0LDEN_infosec

3,422
Followers
782
Following
183
Media
2,190
Statuses

Hack Stuff | Code Stuff | Fitness | Kaizen OSCP | OSWA | OSWE

Niflheim
Joined May 2015
Don't wanna be here? Send us removal request.
Pinned Tweet
@G0LDEN_infosec
Gunnar Andrews
10 months
Say less I'm in! Follow me on threads 🙏
Tweet media one
1
0
23
@G0LDEN_infosec
Gunnar Andrews
2 years
Nothing cooler than seeing @Jhaddix present at DEFCON! Just as cool of a human as you would expect in person! 🤘🔥
Tweet media one
4
3
210
@G0LDEN_infosec
Gunnar Andrews
5 months
Howdy! Just put out a new video about just how easy it is to set up some very easy automation to get anyone and everyone going :) Check it out!
1
54
187
@G0LDEN_infosec
Gunnar Andrews
1 year
I feel like JS analysis is such a big part of successful bug bounty hunting today. But it's hard to find specific methodologies for it 🤔
7
15
110
@G0LDEN_infosec
Gunnar Andrews
1 year
Like many in the BB scene, I am a HUGE fan of @Jhaddix 's Bug Bounty Methodology. But I was always more of a notion fan over Xmind. So this video is how I track my work and take notes during bug bounty hunting using Jason's amazing methods! Check it out!
4
25
99
@G0LDEN_infosec
Gunnar Andrews
3 months
New video! I wanted to make a video going over some recon techniques that people can use to essentially snapshot the internet, and monitor for assets. I talk about what you could use your compute for instead of JUST brute forcing! Check it out!
Tweet media one
1
19
96
@G0LDEN_infosec
Gunnar Andrews
9 months
I spoke twice at @ReconVillage ! Those talks are LIVE on YouTube! Check them out How I Built Recon to Scale with Serverless Architecture: Easy EASM The Zero-Dollar Attack Surface Management Tool (w/ @Jhaddix & @OliviaGalluccii ):
2
21
91
@G0LDEN_infosec
Gunnar Andrews
2 years
Another amazing hacker I met at DEFCON! @InsiderPhD is so fricken nice in person, and thank you so much for the chat/tips 🤘
Tweet media one
1
3
90
@G0LDEN_infosec
Gunnar Andrews
4 months
In true new years fashion.... How to DOMINATE bug bounties in 2024 :) My thoughts and opinions on how you can grow and dominate this year. Check it out :) Sorry sickness delayed this one a ton!
0
11
87
@G0LDEN_infosec
Gunnar Andrews
1 year
Hey everyone! I updated my BB automation architecture, and I wanted to share my thoughts. This video goes into my changes, and why I made them. Check it out :)
0
16
80
@G0LDEN_infosec
Gunnar Andrews
2 years
This new video goes over how I do subdomain recon in my automation. This is a high level overview of how I do things :) I left active enumeration/permutations for another video! Let me know what y'all think! 🤓
2
25
77
@G0LDEN_infosec
Gunnar Andrews
10 months
SUPER excited to share at @ReconVillage how I built my recon framework in the serverless landscape ! If you're around at DEFCON come check out my talk 🤘
Tweet media one
5
7
74
@G0LDEN_infosec
Gunnar Andrews
5 months
If you are into cyber security, bug bounty, red teaming, etc. You should be checking out @Jhaddix 's discord: And you should also 100% be involved in the @ctbbpodcast discord channel: These two channels are necessity IMO 🤘
2
18
76
@G0LDEN_infosec
Gunnar Andrews
1 year
2.5 million subdomains found 🤓
6
2
73
@G0LDEN_infosec
Gunnar Andrews
6 months
New video time! This one goes over how I setup a full ready to go Kubernetes cluster on my home lab servers! If you are trying to run Kubernetes locally to develop cool stuff, check it out! :)
0
17
75
@G0LDEN_infosec
Gunnar Andrews
2 months
Finally dropped my new tool! Gungnir is a continuous CT log scanner that prints out domains to stdout! Check it out!
Tweet media one
3
19
74
@G0LDEN_infosec
Gunnar Andrews
6 months
If you didn't notice, my dude @xnl_h4ck3r made another AMAZING tool! It is a browser extension that does a ton of amazing things that were mentioned in the newest @ctbbpodcast episode! I made a short video so you can see why it's awesome! check it out :)
1
13
69
@G0LDEN_infosec
Gunnar Andrews
6 months
Anyone who watched my first homelab video be ready for the next one. I have some kubernetes clusters set up with some cool stuff going on! And it is all automated thanks to ansible :)
Tweet media one
1
2
66
@G0LDEN_infosec
Gunnar Andrews
1 year
Hey everyone :) I wrote a blog introducing @pdiscoveryio 's new crawler tool Katana! Check it out and try the tool out for yourself! P.S. : A lot of you know I write my automation in Go. Well Katana can also be used as a Go library now as well :)
0
16
64
@G0LDEN_infosec
Gunnar Andrews
2 years
Stopped by the ASM panel @ReconVillage this morning with @NahamSec , @Jhaddix , and @jeff_foley ! Of course if there isn't a picture it didn't happen🤷‍♂️ It has been so fun meeting all these amazing hackers in person 🔥
Tweet media one
0
3
66
@G0LDEN_infosec
Gunnar Andrews
4 months
We broke 3k YT subscribers... And I fricken love all 3062 of you ❤️ it means the world to me
Tweet media one
6
2
62
@G0LDEN_infosec
Gunnar Andrews
2 years
I want to make a community of bug bounty hunters that support each other and hack the planet together :)
9
0
58
@G0LDEN_infosec
Gunnar Andrews
10 months
Hey everyone! I made a little curation of the blogs/resources I am using to "study" bug bounty! I made a repo for it and here is a video explaining why I think you should check it out :)
2
14
57
@G0LDEN_infosec
Gunnar Andrews
1 year
Hello! So as some of you have seen I went down a little Web3 rabbit hole. I made a video compiling all the recommended resources to get started if Web3 bug bounties are something you are interested in exploring! Check it out :)
2
16
56
@G0LDEN_infosec
Gunnar Andrews
3 months
I appreciate every single one of you who have decided to hit the sub button ❤️ having my own little community has been so much fun!
Tweet media one
9
0
57
@G0LDEN_infosec
Gunnar Andrews
2 years
Chill Bug Bounty automation/coding stream! Come hangout and chat :)
0
12
55
@G0LDEN_infosec
Gunnar Andrews
2 months
I seriously never thought it was possible. But it happened! 🔥 Everyone who has come to the streams to hang out, I love each and every one of you!
Tweet media one
11
2
53
@G0LDEN_infosec
Gunnar Andrews
1 year
Golang bug bounty automation. Come hang!
4
12
50
@G0LDEN_infosec
Gunnar Andrews
2 years
Just put out a new video on PwnFox and how it can be such an easy tool for finding critical bugs! This is the first hands on exploitation video! Huge thanks to @zseano for letting me use the platform!
3
18
47
@G0LDEN_infosec
Gunnar Andrews
3 months
This is the type of stuff that makes current AND future creators tentative to share their tools, videos, content, etc. This is extremely disheartening to see coming out of our community tbh.
6
4
49
@G0LDEN_infosec
Gunnar Andrews
9 months
Just dudes being hackers @Jhaddix 🤷‍♂️👨‍💻 Picture cred: @OliviaGalluccii
Tweet media one
2
2
48
@G0LDEN_infosec
Gunnar Andrews
1 year
Whoever shouted out my YouTube channel on @NahamSec 's stream today, you're the real ones ♥️ Watching him check out the channel was so cool! I really appreciate the people recommending my channel to folks.
3
0
46
@G0LDEN_infosec
Gunnar Andrews
16 days
New video! This one shows how the @Jhaddix discord helped me tune CloudRecon, and how I use it to scrape certificates across all IPv4 IPs!
Tweet media one
0
6
48
@G0LDEN_infosec
Gunnar Andrews
2 months
Portswigger and Javascript :) hacker hangout!
2
8
47
@G0LDEN_infosec
Gunnar Andrews
1 year
Okay FINALLY against all odds the new video is out! This one talks about the hacker's mindset, and why it is so important for beginners! Check it out! P.S.: There is a little something for the discord I talk about at the end. Check that out too!
2
9
45
@G0LDEN_infosec
Gunnar Andrews
2 years
I think I am going to start posting youtube videos focused around my own automation / manual hacking experiences. So the topics may be more random but hopefully that will help me post more often :)
0
3
45
@G0LDEN_infosec
Gunnar Andrews
1 year
Hey everyone! The newest video is out! This one is about how SPECIFICALLY I believe you can improve as a bug bounty hunter. Beyond the generic "practice more / do more ctfs" :) Check it out and let me know what you think!
0
13
42
@G0LDEN_infosec
Gunnar Andrews
1 year
Okay so does this mean you get the pentest the ice cream machine... because those things are always offline...
Tweet media one
2
5
40
@G0LDEN_infosec
Gunnar Andrews
2 months
I'm hearing so many people say JavaScript and understanding/using js to your advantage is a top notch BB skill right now. But the "info" seems to still be scattered. Anyone want to name drop folks that have contributed to this so I can take a peek and start a list? :)
7
5
41
@G0LDEN_infosec
Gunnar Andrews
4 months
Other than the Mozilla docs, does anyone have any other sources (videos, blogs, explanations, etc.) on the following topics?: CSP Site isolation Same Origin Policy Frames Same-Site JavaScript execution methods (script, onevent handlers) PostMessage LocalStorage/SessionStorage
15
5
42
@G0LDEN_infosec
Gunnar Andrews
1 year
After spending time on @zseano 's @BugBountyHunt3r platform, reading @Rhynorater 's newest H1 interview, and reviewing other bb hunter's methodology. I noticed a similarity. APPLICATION ANALYSIS! So I made a video about my thoughts and where to learn more!
0
3
39
@G0LDEN_infosec
Gunnar Andrews
2 months
Has anyone done the Senior Web Pentester (CWEE) stuff on HTB academy yet? If so I would love to hear your thoughts :)
11
3
35
@G0LDEN_infosec
Gunnar Andrews
2 months
There is a lot of "trainings" or "courses" flying around the infosec world atm. But if you ARE in the market for some top tier learning, check out @Jhaddix 's TBHM course. I just listened in for the third time, and it is worth every single cent of the price. Gets better every time
1
2
33
@G0LDEN_infosec
Gunnar Andrews
2 years
Am I the only one checking GitHub daily for @Jhaddix 's new sus_params repo?....
7
0
32
@G0LDEN_infosec
Gunnar Andrews
1 year
Over 1,000 people subscribed... WOW! Everyone who follows along and watches my stuff, I seriously have nothing but love for you all! And all the amazing hackers that have shouted out/shared my stuff. It really means the WORLD to me. Thanks so much 🤓
Tweet media one
3
0
33
@G0LDEN_infosec
Gunnar Andrews
2 years
Finally got a new video out! This one talks about my experience with bug bounty automation, and how I am building mine :) I hope you all enjoy it and stick around for the series!
0
7
33
@G0LDEN_infosec
Gunnar Andrews
10 months
Hey everyone! As some know, I took @Jhaddix 's TBHM Live course last weekend. Well, I just wanted to slide a unedited video out there about my thoughts, and if this is something you should consider! Check it out :)
0
9
33
@G0LDEN_infosec
Gunnar Andrews
1 year
New video is out! I wanted to go over a few of the different "types" of automation I have seen people use in bug bounties. Let me know what you think!
0
9
32
@G0LDEN_infosec
Gunnar Andrews
2 years
If any of my bug bounty friends out there I am looking for help. I believe I have a solid automation pipeline for recon set up. I was curious if anyone that has a running list of domains for a wide-scope program would be willing to compare with me:)
9
0
31
@G0LDEN_infosec
Gunnar Andrews
1 year
bug bounty automation work. Come hang! :)
0
4
31
@G0LDEN_infosec
Gunnar Andrews
1 year
Got the new profile picture from @rez0__ ! Thank you so much!
Tweet media one
1
1
31
@G0LDEN_infosec
Gunnar Andrews
2 years
The options for after work on a Friday night: 1. Automation work/coding 2. Get back into leveling up in @BugBountyHunt3r 3. Hack on @SynackRedTeam 🤔🤔
4
1
30
@G0LDEN_infosec
Gunnar Andrews
2 months
The portswigger labs run continues! To GLORY!
0
5
31
@G0LDEN_infosec
Gunnar Andrews
2 years
Day 1 of my year of bug bounty: I started my bug bounty year by going hard on the training platform that seems to get HUGE results for learning, and that is @BugBountyHunt3r ! I already had about 13 vulns, but during my work time today I was able to submit 2 more vulns!
2
1
29
@G0LDEN_infosec
Gunnar Andrews
7 months
New video! I got some servers and started a "home lab". I am planning on continuing the tool dev and automation journey here, and hopefully grow it as I go :) Check it out!
1
3
30
@G0LDEN_infosec
Gunnar Andrews
1 year
1. Sitting at home in the snow making a website 2. @Bugcrowd sends the private invite 3. Hunter mode => ON Going to be a long night :P
2
1
28
@G0LDEN_infosec
Gunnar Andrews
4 months
Just re-watched on old bounty Thursday's that @stokfredrik used to put on. Man I miss those!
2
1
29
@G0LDEN_infosec
Gunnar Andrews
1 year
As 2022 comes to a close in a week, I just wanted to say a huge thank you everyone I interacted with this year. All the people that chat with me, mentor me, work with me, and much more. I love you all 🙂Here's to 2023 🤘
3
0
28
@G0LDEN_infosec
Gunnar Andrews
1 year
Hey everyone! For anyone thinking of diving head first into bug bounties in 2023, check out my new video where I give some high level advice of stuff I have done as well as share some knowledge other BB hunters have shared with me :)
0
8
28
@G0LDEN_infosec
Gunnar Andrews
1 year
It was super cool watching @NahamSec and @Jhaddix hop back on a stream today. I am super excited for all the live recon streams to start back up 🤘
0
1
28
@G0LDEN_infosec
Gunnar Andrews
1 month
We. Go. Gym 💪 Happy Friday nerds 🤘❤️
7
0
28
@G0LDEN_infosec
Gunnar Andrews
5 months
I attended @Jhaddix 's hacking your brand course today. And I gotta say it honestly was an absolute GAME CHANGER👌
0
1
27
@G0LDEN_infosec
Gunnar Andrews
2 months
Coding tools maybe portswigger! Come hackers!
0
3
27
@G0LDEN_infosec
Gunnar Andrews
1 year
A few people asked me to explain how I handle my data and connect to a database with my containerized automation. Well my new video is a demo to explain how I do it and why! Enjoy :)
1
7
27
@G0LDEN_infosec
Gunnar Andrews
9 months
Final few lifts before @defcon ! 💪💪 #wehackhealth
Tweet media one
4
0
26
@G0LDEN_infosec
Gunnar Andrews
11 months
Toxicity in the bug bounty space just makes me sad. Sadly there are folks that think the fastest way to build themselves up is to just tear others down. Any people who follow me in the scene, please PLEASE be a positive force in the community.
2
1
26
@G0LDEN_infosec
Gunnar Andrews
1 year
It is done! I have decided the best place to show off the new stuff I have been building is at DEFCON! Fingers crossed 🤞
Tweet media one
2
2
25
@G0LDEN_infosec
Gunnar Andrews
8 months
A few weeks ago I spoke to @CharlieEriksen about @WeaselJs !! I just wanted to follow with a little demo going over how easy it is to get going, and what it looks like to run the tool! Check it out :)
0
7
25
@G0LDEN_infosec
Gunnar Andrews
1 year
@TakSec If you like JS link finder as an extension you should try/compare it to @xnl_h4ck3r 's tool!
2
8
23
@G0LDEN_infosec
Gunnar Andrews
2 months
Be advised!! The community already caught some errors in the first version of gungnir! So I made some changes today to fix them all! Please check the readme and download the newest version :)
0
3
25
@G0LDEN_infosec
Gunnar Andrews
9 months
Go watch :) This was such a fun time and thanks for having me!🤘
@h4x0r_fr34k
VAIDIK PANDYA
9 months
Episode 13 of hackcast is out with @G0LDEN_infosec About automation in bug bounty Link:
0
0
7
1
8
25
@G0LDEN_infosec
Gunnar Andrews
6 days
Yo the dude in that video looks like me 👀
@NahamSec
Ben Sadeghipour
6 days
In Recon: If You're Not First You're Last
Tweet media one
2
21
214
2
4
33
@G0LDEN_infosec
Gunnar Andrews
2 years
First Mental Hacking video is live! These videos will be about mindset, improvement, etc. This first one is all about how to improve in bug bounties, web hacking, or really any skill! Check it out! :)
4
3
23
@G0LDEN_infosec
Gunnar Andrews
9 months
EVERYONE needs to go read this! @DanielMiessler is speaking so much truth and bringing so much knowledge in this! Check it out!
1
1
24
@G0LDEN_infosec
Gunnar Andrews
7 months
👀👀👀
Tweet media one
4
0
23
@G0LDEN_infosec
Gunnar Andrews
1 year
How does one do true "security research"?? Like is it actually diving into RFCs, white papers, and Google scholar? I am actually genuinely curious/asking
9
1
23
@G0LDEN_infosec
Gunnar Andrews
1 month
It's time!! Got some new looks coming up!
6
1
23
@G0LDEN_infosec
Gunnar Andrews
2 years
Best resources to deep dive DNS for bug hunters and security researchers? 👀
3
5
21
@G0LDEN_infosec
Gunnar Andrews
2 years
Finally episode 4 of Gamified Hacking is out! This one is all about data driven bug bounty. What are some ways of handling all the data you gather, and why data is important! Please check it out and share if you like it :)
1
1
20
@G0LDEN_infosec
Gunnar Andrews
2 months
When I get home I am uploading the vod of yesterday's stream with @xssdoctor for all those who asked :)
2
0
21
@G0LDEN_infosec
Gunnar Andrews
2 months
HUGE shout out to @JXoaT and the @hackthebox_eu crew for giving me the chance the experience the "Senior Web Penetration Tester" Learning path! I can't wait to learn a ton and share my experience 🔥🔥
2
1
21
@G0LDEN_infosec
Gunnar Andrews
6 months
IMO... The perfect combo for bug bounty collaboration: 1. The super exploiter: tons of knowledge, tricks, in-depth knowledge. 2. The security engineer/dev: Able to automate and expand the attack surface and exploitation reach of member #1
1
2
21
@G0LDEN_infosec
Gunnar Andrews
1 year
I have to say I have a "new" weird goal with BB. Seeing all these elite BB hunters that have such close friendships with each other through this field. THAT is what I want. I want to be a part of that ✋
2
0
20
@G0LDEN_infosec
Gunnar Andrews
9 months
Am I a psychopath for really liking the Windows + WSL setup for development and hacking? It has been working so nice so far!
8
1
20
@G0LDEN_infosec
Gunnar Andrews
1 year
I wanted to put out my 2023 "resolutions". This year I will be focusing on 5 things. In true @JamesClear fashion these 5 things are SYSTEMS and not goals. My hope is at the end of the year I can report back on what output these systems produced. The five are the following:
2
1
19
@G0LDEN_infosec
Gunnar Andrews
1 year
Check it out l! 📈
@NahamSec
Ben Sadeghipour
1 year
I made $100,000+ Hacking on @hacker0x01 and @bugcrowd ! 🎥👉🏼
Tweet media one
22
49
462
0
3
20
@G0LDEN_infosec
Gunnar Andrews
2 years
New video alert! Gamified hacking episode 1 is out! This one is all about gathering in scope domains without missing any possible attack surface. This could include scopes where all assets are in scope! Check it out and let me know what you think! 🤓
1
6
20
@G0LDEN_infosec
Gunnar Andrews
1 year
Chill short stream! Coding some BB automation!
1
3
19
@G0LDEN_infosec
Gunnar Andrews
2 months
Look out for us 👀 we are on the come up I swear it 🔥🔥
@BadAt_Computers
Roll4Combat
2 months
@G0LDEN_infosec told me he already started on HTB- CWEE so I guess its my time to level up and go through this material. I absolutely loved the CBBH as it was my first certification and really looking forward to this Senior Penetration Testing Path.
Tweet media one
3
0
15
1
1
19
@G0LDEN_infosec
Gunnar Andrews
1 year
I find myself counting down the days until the next @ctbbpodcast pod🤷‍♂️ if you haven't listened yet and you are in bug bounties, you're missing out BIG! 👊
2
5
19
@G0LDEN_infosec
Gunnar Andrews
2 months
Today's activities: - Gym - Pentest - Stream - Game Perfect Sunday 👌👌
2
1
19