Skip to main content
buildradar
Sign in
Topic · bugbounty

bugbounty

Tracked open-source repos tagged bugbounty, sorted by stars.

Repos
157
Total stars
494,130
Avg. stars
3,147
Share
0.03%

Topics that frequently appear alongside bugbounty on the same repo.

Recent risers

Repos created in the last 90 days, tagged bugbounty.

No new repos tagged with this topic in the last 90 days.

  • PayloadsAllTheThings@swisskyrepo

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    80,589+0Star change over the last 7 days
  • dirsearch@maurosoria

    Web path scanner

    14,684+0Star change over the last 7 days
  • subfinder@projectdiscovery

    Fast passive subdomain enumeration tool.

    14,363+0Star change over the last 7 days
  • nuclei-templates@projectdiscovery

    Community curated list of templates for the nuclei engine to find security vulnerabilities.

    12,905+0Star change over the last 7 days
  • A list of resources for those interested in getting started in bug bounties

    12,218+0Star change over the last 7 days
  • hetty@dstotijn

    An HTTP toolkit for security research.

    12,009+0Star change over the last 7 days
  • A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

    11,119+0Star change over the last 7 days
  • bbot@blacklanternsecurity

    The recursive internet scanner for hackers. 🧡

    10,528+0Star change over the last 7 days
  • httpx@projectdiscovery

    httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

    10,345+0Star change over the last 7 days
  • OneForAll@shmilylty

    OneForAll是一款功能强大的子域收集工具

    10,041+0Star change over the last 7 days
  • wstg@OWASP

    The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

    9,779+0Star change over the last 7 days
  • rengine@yogeshojha

    reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

    8,807+0Star change over the last 7 days
  • reconftw@six2dez

    reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

    8,053+0Star change over the last 7 days
  • HowToHunt@KathanP19

    Collection of methodology and test case for various web vulnerabilities.

    7,193+0Star change over the last 7 days
  • One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

    6,729+0Star change over the last 7 days
  • osmedeus@j3ssie

    A Modern Orchestration Engine for Security

    6,540+0Star change over the last 7 days
  • hackerone-reports@reddelexc

    Top disclosed reports from HackerOne

    6,508+0Star change over the last 7 days
  • apkleaks@dwisiswant0

    Scanning APK file for URIs, endpoints & secrets.

    6,277+0Star change over the last 7 days
  • A curated list of various bug bounty tools

    6,230+0Star change over the last 7 days
  • scan4all@GhostTroops

    Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

    6,169+0Star change over the last 7 days
  • commix@commixproject

    Automated All-in-One OS Command Injection Exploitation Tool

    5,831+0Star change over the last 7 days
  • can-i-take-over-xyz@EdOverflow

    "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

    5,794+0Star change over the last 7 days
  • dalfox@hahwul

    🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

    5,269+0Star change over the last 7 days
  • hakrawler@hakluke

    Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

    5,117+0Star change over the last 7 days
  • ⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

    5,050+0Star change over the last 7 days
  • interactsh@projectdiscovery

    An OOB interaction gathering server and client library

    4,514+0Star change over the last 7 days
  • malicious-pdf@jonaslejon

    💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh

    4,295+0Star change over the last 7 days
  • knockpy@guelfoweb

    Knock Subdomain Scan

    4,183+0Star change over the last 7 days
  • Claude-BugHunter@elementalsouls

    A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.

    4,118+0Star change over the last 7 days
  • Fuzzing101@antonio-morales

    An step by step fuzzing tutorial. A GitHub Security Lab initiative

    3,821+0Star change over the last 7 days
← Back to topics