# Projects

OSS work at ProjectDiscovery (Nuclei, Alterx, and the rest of the toolkit) plus AI-security research and the tools that got him hired.

## ai-security research

- [Neo: evals & benchmarking](https://projectdiscovery.io/blog/neo-black-box-dast-capabilities) · ProjectDiscovery's offensive-security AI agent, and the open question of whether an autonomous agent can actually hack. Builds the harness that measures it: evals at scale, benchmarking, and the trace observability that shows what the agent actually did on a target. `neo · evals · benchmarking · observability`

## projectdiscovery oss

- [Nuclei](https://github.com/projectdiscovery/nuclei) · The vulnerability scanner much of offensive security runs on. Core team through the v3 era, now on Neo. `go · ~29k★ · core team, v3 era`
- [Alterx](https://github.com/projectdiscovery/alterx) · Subdomain permutation generator driven by patterns instead of a static wordlist: define the patterns, get candidate hostnames to enumerate before a scan. `go · ~940★ · author`
- [Subfinder, Katana, httpx, tlsx, Cloudlist, Cvemap](https://github.com/projectdiscovery) · ProjectDiscovery's recon toolkit: the scanners and enrichment tools teams chain to map an attack surface. Ongoing contributor across the stack. `go · katana ~16.4k★ · tlsx ~1,087★`

## earlier tools

- [Talosplus](https://github.com/tarunKoyalwar/talosplus) · Recon-automation framework in Go: plain bash scripts become a managed parallel execution graph. One of the two tools that landed the ProjectDiscovery job. `go · ~92★`
- [Sandman](https://github.com/tarunKoyalwar/Sandman) · Note-taking and target-tracking GUI for pentesters, wired into the recon pipeline. The other half of what landed the ProjectDiscovery job. `go · ~42★ · archived`

---

tarun@no-ide.dev · [github](https://github.com/tarunKoyalwar) · [x](https://x.com/KoyalwarTarun) · [linkedin](https://www.linkedin.com/in/tarun-koyalwar) · [medium](https://medium.com/@zealousme)

agents start at [/agents.md](/agents.md)
