bugbounty
Tracked open-source repos tagged bugbounty, sorted by stars.
- #91
An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.
★ 1,295+0Star change over the last 7 days - #92
80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒
★ 1,278+0Star change over the last 7 days - #93
Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting
★ 1,278+0Star change over the last 7 days - #94★ 1,264+0Star change over the last 7 days
- #95★ 1,217+0Star change over the last 7 days
- #96
Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second
★ 1,217+0Star change over the last 7 days - #97
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
★ 1,202+0Star change over the last 7 days - #98
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
★ 1,193+0Star change over the last 7 days - #99
Twitter vulnerable snippets
★ 1,176+0Star change over the last 7 days - #100
🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), OpenAI (GPTBot) and other with daily updates.
★ 1,174+0Star change over the last 7 days - #101
Awesome cloud enumerator
★ 1,146+0Star change over the last 7 days - #102
"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.
★ 1,105+2Star change over the last 7 days - #103★ 1,080+5Star change over the last 7 days
- #104
MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats.
★ 1,056+3Star change over the last 7 days - #105
Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.
★ 1,054+0Star change over the last 7 days - #106
Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place
★ 1,048+1Star change over the last 7 days - #107
Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.
★ 1,038+0Star change over the last 7 days - #108
⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)
★ 1,024+1Star change over the last 7 days - #109
基于ARL-V2.6.2修改后的版本
★ 1,005+0Star change over the last 7 days - #110
AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual TUI. It is designed to automate security assessments, penetration testing, and bug bounty reconnaissance — without any API keys or cloud dependency.
★ 986+6Star change over the last 7 days - #111
1337 Wordlists for Bug Bounty Hunting
★ 983+1Star change over the last 7 days - #112
This Repository is a collection of different ethical hacking tools and malware's for penetration testing and research purpose written in python, ruby, rust, c++, go and c.
★ 977+39Star change over the last 7 days - #113
SpiderSuite (web security crawler) releases, wiki and roadmap
★ 976+4Star change over the last 7 days - #114
Subdomain and target enumeration tool built for offensive security testing
★ 974+1Star change over the last 7 days - #115
AppSec Payloads Arsenal for Pentration Tester and Bug Bounty Hunters
★ 947+3Star change over the last 7 days - #116★ 940+1Star change over the last 7 days
- #117
A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
★ 922+0Star change over the last 7 days - #118
My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.
★ 921+1Star change over the last 7 days - #119
A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.
★ 910+3Star change over the last 7 days - #120
Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!
★ 909+0Star change over the last 7 days