bugbounty
Tracked open-source repos tagged bugbounty, sorted by stars.
- #31
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
★ 3,788+2Star change over the last 7 days - #32
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
★ 3,758+2Star change over the last 7 days - #33
This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter
★ 3,635-1Star change over the last 7 days - #34
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
★ 3,527+1Star change over the last 7 days - #35
pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching
★ 3,387-2Star change over the last 7 days - #36★ 3,344+0Star change over the last 7 days
- #37
Rockyou for web fuzzing
★ 3,234+2Star change over the last 7 days - #38
A collection of awesome one-liner scripts especially for bug bounty tips.
★ 3,194+3Star change over the last 7 days - #39★ 3,169+2Star change over the last 7 days
- #40
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
★ 3,166+5Star change over the last 7 days - #41
Quickly discover exposed hosts on the internet using multiple search engines.
★ 3,044+1Star change over the last 7 days - #42★ 2,995+1Star change over the last 7 days
- #43
Web Fuzzing Box - Web 模糊测试字典与一些Payloads
★ 2,793+1Star change over the last 7 days - #44★ 2,743+5Star change over the last 7 days
- #45★ 2,574+8Star change over the last 7 days
- #46
Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting
★ 2,431+0Star change over the last 7 days - #47
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
★ 2,387+1Star change over the last 7 days - #48
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
★ 2,381+1Star change over the last 7 days - #49★ 2,370+0Star change over the last 7 days
- #50
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
★ 2,333+2Star change over the last 7 days - #51★ 2,301+1Star change over the last 7 days
- #52
Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.
★ 2,238+2Star change over the last 7 days - #53
Tips and Tutorials for Bug Bounty and also Penetration Tests.
★ 2,117+1Star change over the last 7 days - #54★ 2,111+1Star change over the last 7 days
- #55★ 2,093+0Star change over the last 7 days
- #56
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.
★ 1,889+3Star change over the last 7 days - #57
🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.
★ 1,869+26Star change over the last 7 days - #58
For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙
★ 1,848+1Star change over the last 7 days - #59
A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities.
★ 1,848+3Star change over the last 7 days - #60
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
★ 1,820-1Star change over the last 7 days