Skip to main content
buildradar
Sign in
Topic · bugbounty

bugbounty

Tracked open-source repos tagged bugbounty, sorted by stars.

157 repos
  • webcopilot@h4r5h1t

    An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.

    1,295+0Star change over the last 7 days
  • Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting

    1,278+4Star change over the last 7 days
  • nuclei-wordfence-cve@topscoder

    80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

    1,278+0Star change over the last 7 days
  • scilla@edoardottt

    Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

    1,264+1Star change over the last 7 days
  • shortscan@bitquark

    An IIS short filename enumeration tool

    1,217+2Star change over the last 7 days
  • ksubdomain@boy-hack

    Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second

    1,217+4Star change over the last 7 days
  • Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).

    1,202+2Star change over the last 7 days
  • leaky-paths@ayoubfathi

    A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.

    1,193+0Star change over the last 7 days
  • Twitter vulnerable snippets

    1,176+0Star change over the last 7 days
  • ipranges@lord-alfred

    🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), OpenAI (GPTBot) and other with daily updates.

    1,174+5Star change over the last 7 days
  • Awesome cloud enumerator

    1,146+1Star change over the last 7 days
  • "Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.

    1,104+1Star change over the last 7 days
  • jwt-hack@hahwul

    JSON Web Token Hack Toolkit

    1,079+5Star change over the last 7 days
  • magicRecon@robotshell

    MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats.

    1,055+3Star change over the last 7 days
  • sitedorks@Zarcolio

    Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

    1,054-1Star change over the last 7 days
  • cent@xm1k3

    Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

    1,048+2Star change over the last 7 days
  • mantis@PhonePe

    Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.

    1,038-1Star change over the last 7 days
  • karma_v2@Dheerajmadhukar

    ⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

    1,024+3Star change over the last 7 days
  • 基于ARL-V2.6.2修改后的版本

    1,005-1Star change over the last 7 days
  • fuzz4bounty@0xPugal

    1337 Wordlists for Bug Bounty Hunting

    983+0Star change over the last 7 days
  • airecon@pikpikcu

    AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual TUI. It is designed to automate security assessments, penetration testing, and bug bounty reconnaissance — without any API keys or cloud dependency.

    983+7Star change over the last 7 days
  • SpiderSuite@spidersuite

    SpiderSuite (web security crawler) releases, wiki and roadmap

    974+1Star change over the last 7 days
  • subscraper@m8sec

    Subdomain and target enumeration tool built for offensive security testing

    974+1Star change over the last 7 days
  • Hacking-Tools@aw-junaid

    This Repository is a collection of different ethical hacking tools and malware's for penetration testing and research purpose written in python, ruby, rust, c++, go and c.

    973+39Star change over the last 7 days
  • AppSec-Payloads@sh377c0d3

    AppSec Payloads Arsenal for Pentration Tester and Bug Bounty Hunters

    946+2Star change over the last 7 days
  • mantra@brosck

    「🔑」A tool used to hunt down API key leaks in JS files and pages

    939+0Star change over the last 7 days
  • BugBountyScanner@chvancooten

    A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.

    923+1Star change over the last 7 days
  • security-tools@bl4de

    My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.

    921+1Star change over the last 7 days
  • Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!

    910+1Star change over the last 7 days
  • urlfinder@projectdiscovery

    A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

    908+6Star change over the last 7 days
← Back to topics