Status Open to collaboration & security research.

Tint Naing Win (devtint)

Security Engineer and Tool Developer specializing in offensive security automation, vulnerability research, and custom reconnaissance pipelines.

Bangkok, Thailand Kasem Bundit University Live Portfolio
Tint Naing Win Profile Avatar
36+ Repositories
585+ Contributions
9+ Security Utilities

About me

I design and build specialized tools that automate complex workflows in penetration testing, network auditing, and vulnerability scanning. My security philosophy focuses on developer-first tools, combining clean static code analysis with robust automated scanner orchestration to identify flaws early.

Currently studying Digital Technology Innovation at Kasem Bundit University, I actively conduct independent vulnerability research and write utilities using Python, TypeScript, and Go. I am highly comfortable building automated cloud setups, custom Telegram administrators, proxy pipelines, and terminal utilities.

Featured security tooling & research

Vulnerability Management

NUCLEI_CNM

Enterprise vulnerability command-center for orchestrating Nuclei scanners. Features multi-node scanner scheduling, live findings reporting, AI template suggestions (via Groq API), and Shodan scanning integrations.

  • TypeScript
  • React
  • Node.js
  • Groq API
git clone https://github.com/devtint/NUCLEI_CNM
Security Auditing

SecurityHeaderScanner

High-speed HTTP compliance scanner checking server configurations against OWASP web security standards. Validates CSP, HSTS, CORS, X-Frame-Options, and prints formatted CLI results.

  • Python
  • HTTPX
  • Rich
git clone https://github.com/devtint/SecurityHeaderScanner
Automation

GeminiSheeridVerify

SheerID identity verification automation pipeline for acquiring developer API access. Implements background task queues, proxy rotation, Telegram warnings, and custom TLS fingerprinting.

  • Python
  • curl_cffi
  • Asyncio
git clone https://github.com/devtint/GeminiSheeridVerify
Reconnaissance

Js-And-Endpoints-scanner

Static reconnaissance scanning helper (CLI & extension) built to parse client-side JS bundles. Discovers hidden API paths, unlinked API routing endpoints, and hardcoded secrets.

  • JavaScript
  • Node.js
  • Regex
git clone https://github.com/devtint/Js-And-Endpoints-scanner
Network Audit

CAPTIVE_AUDIT

Interactive auditing utility for inspecting wireless captive portal authentication models. Audits DNS/DHCP leaks, tests bypass methods, and generates detailed PDF reports.

  • Python
  • Scapy
  • Shell
  • TShark
git clone https://github.com/devtint/CAPTIVE_AUDIT
VPN Automation

WarpConfGen

WireGuard configuration generator script and Telegram bot assisting in the deployment of secure, split-tunnel Cloudflare WARP client configurations across devices.

  • Python
  • Telegram API
  • WireGuard
git clone https://github.com/devtint/WarpConfGen
Offensive Payload

r3verse_shells_gen

Interactive CLI utility and snippets bundle generating reverse-shell payloads across major networking protocols and programming languages (Bash, Python, Netcat, PowerShell, PHP, Ruby).

  • JavaScript
  • Shell
  • Python
git clone https://github.com/devtint/r3verse_shells_gen
DevSecOps Infrastructure

free-stack

DevSecOps architectural guides, configuration parameters, and deployment templates optimized for securely deploying production workloads on free-tier cloud platforms (Vercel, Supabase, Cloudflare).

  • YAML
  • Docker
  • Shell
  • CI/CD
git clone https://github.com/devtint/free-stack
API Security

API_PENTEST

Automated security scanning framework built for REST and GraphQL APIs. Scans endpoint schemas, maps routes, and audits for IDOR flaws, query injection, and schema disclosure.

  • Python
  • GraphQL
  • REST
  • Security Testing
git clone https://github.com/devtint/API_PENTEST

Technical competencies

Languages

  • Python
  • TypeScript
  • JavaScript
  • Bash scripting
  • Go / C

Security & Tools

  • Nuclei scanning
  • Burp Suite
  • OWASP Web security
  • Captive portal audits
  • API vulnerability testing

Frameworks & Cloud

  • Node.js / Express
  • React / Next.js
  • FastAPI
  • Vercel / Supabase

Infrastructure & Ops

  • Git version control
  • Linux environments
  • Docker containerization
  • WireGuard deployments
  • CI/CD workflow basics

Get in touch