Skip to main content
buildradar
Sign in
Topic · bugbounty

bugbounty

Tracked open-source repos tagged bugbounty, sorted by stars.

157 repos
  • Findomain@Findomain

    The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.

    3,788+2Star change over the last 7 days
  • cariddi@edoardottt

    Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

    3,758+2Star change over the last 7 days
  • This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter

    3,635-1Star change over the last 7 days
  • An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.

    3,527+1Star change over the last 7 days
  • pagodo@opsdisk

    pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching

    3,387-2Star change over the last 7 days
  • NoSQLMap@codingo

    Automated NoSQL database enumeration and web application exploitation tool.

    3,344+0Star change over the last 7 days
  • Rockyou for web fuzzing

    3,234+2Star change over the last 7 days
  • A collection of awesome one-liner scripts especially for bug bounty tips.

    3,194+3Star change over the last 7 days
  • S3Scanner@sa7mon

    Scan for misconfigured S3 buckets across S3-compatible APIs!

    3,169+2Star change over the last 7 days
  • ParamSpider@devanshbatham

    Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

    3,166+5Star change over the last 7 days
  • uncover@projectdiscovery

    Quickly discover exposed hosts on the internet using multiple search engines.

    3,044+1Star change over the last 7 days
  • gospider@jaeles-project

    Gospider - Fast web spider written in Go

    2,995+1Star change over the last 7 days
  • Web-Fuzzing-Box@gh0stkey

    Web Fuzzing Box - Web 模糊测试字典与一些Payloads

    2,793+1Star change over the last 7 days
  • reFlutter@Impact-I

    Flutter Reverse Engineering Framework

    2,743+5Star change over the last 7 days
  • caido@caido

    🚀 Caido releases, wiki and roadmap

    2,574+8Star change over the last 7 days
  • Sudomy@screetsec

    Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting

    2,431+0Star change over the last 7 days
  • Tiny-XSS-Payloads@terjanq

    A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

    2,387+1Star change over the last 7 days
  • gitGraber@hisxo

    gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...

    2,381+1Star change over the last 7 days
  • jaeles@jaeles-project

    The Swiss Army knife for automated Web Application Testing

    2,370+0Star change over the last 7 days
  • ezXSS@ssl

    ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

    2,333+2Star change over the last 7 days
  • BruteX@1N3

    Automatically brute force all services running on a target.

    2,301+1Star change over the last 7 days
  • puredns@d3mondev

    Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.

    2,238+2Star change over the last 7 days
  • Tips and Tutorials for Bug Bounty and also Penetration Tests.

    2,117+1Star change over the last 7 days
  • subjack@haccer

    DNS Takeover tool written in Go

    2,111+1Star change over the last 7 days
  • x8@Sh1Yo

    Hidden parameters discovery suite

    2,093+0Star change over the last 7 days
  • SubDomainizer@nsonaniya2010

    A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

    1,889+3Star change over the last 7 days
  • nomore403@devploit

    🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.

    1,869+26Star change over the last 7 days
  • top25-parameter@lutfumertceylan

    For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙

    1,848+1Star change over the last 7 days
  • A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities.

    1,848+3Star change over the last 7 days
  • BlackWidow@1N3

    A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

    1,820-1Star change over the last 7 days
← Back to topics