bug-bounty
Tracked open-source repos tagged bug-bounty, sorted by stars.
Related topics
Topics that frequently appear alongside bug-bounty on the same repo.
Recent risers
Repos created in the last 90 days, tagged bug-bounty.
- #1
Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.
★ 2,048 - #2
Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
★ 1,224 - #3
Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
★ 758 - #4
Pentest Harness — Heaven for Hackers. A self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Bring your own AI model API; sessions stay local.
★ 340 - #5
🛡️ Comprehensive Cybersecurity Arsenal, Bug Bounty Payloads & Security Audit Tools by IKONA ONI
★ 117
- #1
A collection of various awesome lists for hackers, pentesters and security researchers
★ 119,570+248Star change over the last 7 days - #2★ 60,206+913Star change over the last 7 days
- #3★ 14,684+13Star change over the last 7 days
- #4
A list of resources for those interested in getting started in bug bounties
★ 12,218+12Star change over the last 7 days - #5
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
★ 8,807+7Star change over the last 7 days - #6
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
★ 8,053+21Star change over the last 7 days - #7★ 7,006+2Star change over the last 7 days
- #8
AI-powered bug bounty hunting toolkit that works with or without subscription.
★ 4,670+76Star change over the last 7 days - #9
The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
★ 4,418+2Star change over the last 7 days - #10
Applied offensive security with Rust - https://kerkour.com/black-hat-rust
★ 4,395+2Star change over the last 7 days - #11★ 4,376+4Star change over the last 7 days
- #12
📡 Comprehensive collection of OSINT tools for cybersecurity professionals, researchers, and bug bounty hunters. Topics: information gathering, reverse search, red team, trust & safety, AI.
★ 4,344+23Star change over the last 7 days - #13
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
★ 4,118+282Star change over the last 7 days - #14
A collection of awesome one-liner scripts especially for bug bounty tips.
★ 3,194+3Star change over the last 7 days - #15★ 2,634+3Star change over the last 7 days
- #16★ 2,520+5Star change over the last 7 days
- #17
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go, Claude API, and 7+ native security tools.
★ 2,440+46Star change over the last 7 days - #18
ChatGPT Plus/Team/Pro 订阅协议端到端重放工具集 · hCaptcha 视觉求解器 · 反欺诈机制实证研究 / End-to-end protocol replay toolkit for ChatGPT Plus/Team/Pro subscription with from-scratch hCaptcha solver and empirical anti-fraud research
★ 2,236+7Star change over the last 7 days - #19
Open-source AI-powered offensive security harness for automated penetration testing.
★ 2,221+160Star change over the last 7 days - #20
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
★ 2,189+17Star change over the last 7 days - #21
Collection of quality safety articles. Awesome articles.
★ 2,116+0Star change over the last 7 days - #22★ 2,111+1Star change over the last 7 days
- #23
Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.
★ 2,048+22Star change over the last 7 days - #24
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.
★ 1,889+3Star change over the last 7 days - #25
A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities.
★ 1,848+3Star change over the last 7 days - #26
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
★ 1,813+2Star change over the last 7 days - #27★ 1,755+19Star change over the last 7 days
- #28
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
★ 1,643+11Star change over the last 7 days - #29
A collection of one-liners for bug bounty hunting.
★ 1,630+1Star change over the last 7 days - #30★ 1,604+1Star change over the last 7 days