Skip to main content
buildradar
Sign in
Topic · bug-bounty

bug-bounty

Tracked open-source repos tagged bug-bounty, sorted by stars.

63 repos
  • ScopeSentry@Autumn-27

    ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes

    1,601+9Star change over the last 7 days
  • clairvoyance@nikitastupin

    Obtain GraphQL API schema even if the introspection is disabled

    1,512+5Star change over the last 7 days
  • API Security Project aims to present unique attack & defense methods in API Security field

    1,447+1Star change over the last 7 days
  • A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and enhance your hacking toolkit!

    1,383+1Star change over the last 7 days
  • v3-periphery@Uniswap

    🦄 🦄 🦄 Peripheral smart contracts for interacting with Uniswap v3

    1,332-1Star change over the last 7 days
  • webcopilot@h4r5h1t

    An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.

    1,295+0Star change over the last 7 days
  • recon-skills@uphiago

    Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh

    1,224+18Star change over the last 7 days
  • ipranges@lord-alfred

    🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), OpenAI (GPTBot) and other with daily updates.

    1,174+5Star change over the last 7 days
  • diodb@disclose

    Open-source vulnerability disclosure and bug bounty program database

    1,082+3Star change over the last 7 days
  • vigolium@vigolium

    Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

    1,060+7Star change over the last 7 days
  • resolvers@trickest

    The most exhaustive list of reliable DNS resolvers.

    1,048+2Star change over the last 7 days
  • reconmap@reconmap

    Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.

    975+0Star change over the last 7 days
  • xalgorix@xalgorix

    Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

    960+21Star change over the last 7 days
  • wpprobe@Chocapikk

    A fast WordPress plugin enumeration tool

    943+6Star change over the last 7 days
  • security-tools@bl4de

    My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.

    921+1Star change over the last 7 days
  • sectemplates@securitytemplates

    Open source templates you can use to bootstrap your security programs

    915+1Star change over the last 7 days
  • Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!

    910+1Star change over the last 7 days
  • DataSurgeon@Drew-Alleman

    Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

    904+2Star change over the last 7 days
  • Work in progress...

    845+3Star change over the last 7 days
  • Collection of Facebook Bug Bounty Writeups

    845-1Star change over the last 7 days
  • pentest-agents@H-mmer

    Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

    815+3Star change over the last 7 days
  • Cybermes@Zyrexnn

    Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.

    758+102Star change over the last 7 days
  • numasec@FrancescoStabile

    The AI Agent for Cyber Security.

    749+137Star change over the last 7 days
  • xurlfind3r@hueristiq

    A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directly with the target but instead gathers data that is already publicly available.

    722+3Star change over the last 7 days
  • keyFinder@momenbasel

    Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

    706+2Star change over the last 7 days
  • cain-agent@cdxiaodong

    Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK

    692Star change over the last 7 days
  • scant3r@MindPatch

    ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )

    684-2Star change over the last 7 days
  • Bug-Bounty@AnLoMinus

    Bug Bounty ~ Awesomes | Books | Cheatsheets | Checklists | Tools | Wordlists | More

    663+3Star change over the last 7 days
  • goop@nyancrimew

    Yet another tool to dump a git repository from a website, focused on as-complete-as-possible dumps and handling weird edge-cases.

    653+0Star change over the last 7 days
  • SQLiDetector@eslam3kl

    Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.

    642+2Star change over the last 7 days
← Back to topics