bugbounty
Tracked open-source repos tagged bugbounty, sorted by stars.
- #121
A curated list of Smart Contract Security materials and resources For Researchers
★ 905-1Star change over the last 7 days - #122
These are my checklists which I use during my hunting.
★ 894+3Star change over the last 7 days - #123★ 893+3Star change over the last 7 days
- #124
The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of Netlas.io.
★ 888-1Star change over the last 7 days - #125
An OSINT tool to quickly extract IP and URL endpoints from APKs by disassembling and decompiling
★ 874-1Star change over the last 7 days - #126
Collection of Facebook Bug Bounty Writeups
★ 845+0Star change over the last 7 days - #127
⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.
★ 843-2Star change over the last 7 days - #128
An insane list of all dorks taken from everywhere from various different sources.
★ 824-1Star change over the last 7 days - #129
Unleash the power of cloud
★ 822+1Star change over the last 7 days - #130
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
★ 811+1Star change over the last 7 days - #131
SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty
★ 809+1Star change over the last 7 days - #132
Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.
★ 806+2Star change over the last 7 days - #133
An OSINT tool that helps detect members of a company with leaked credentials
★ 791+0Star change over the last 7 days - #134
A heavily armed customizable phishing tool for educational purpose only
★ 735+1Star change over the last 7 days - #135★ 733+1Star change over the last 7 days
- #136
🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️
★ 732+0Star change over the last 7 days - #137
Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
★ 707+2Star change over the last 7 days - #138
Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories ) + Web App
★ 705+2Star change over the last 7 days - #139
Chiasmodon is an OSINT tool designed to assist in the process of gathering information about a target domain. Its primary functionality revolves around searching for domain-related data, including domain emails, domain credentials, CIDRs , ASNs , and subdomains, the tool also allows users to search Google Play application ID.
★ 698+1Star change over the last 7 days - #140
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
★ 689+1Star change over the last 7 days - #141
ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )
★ 684-2Star change over the last 7 days - #142
A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀
★ 676+1Star change over the last 7 days - #143
Bug Bounty ~ Awesomes | Books | Cheatsheets | Checklists | Tools | Wordlists | More
★ 663+3Star change over the last 7 days - #144
Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.
★ 644+4Star change over the last 7 days - #145
The classic launcher, evolved. Fast, Go-based command library equipped with 200+ cybersecurity cheat-sheets. Just install and start hacking.
★ 634+9Star change over the last 7 days - #146
Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
★ 630+2Star change over the last 7 days - #147
🧿 AutorizePro是一款强大越权检测 Burp 插件,通过增加 AI 辅助分析 && 进一步优化检测逻辑,大幅降低误报率,提升越权漏洞检出效率。 [ AutorizePro is a authorization enforcement detection extension for burp suite. By adding Ai-assisted analysis, it significantly reduces the false positive rate and improves the efficiency of vulnerability detection.
★ 614+3Star change over the last 7 days - #148★ 594+2Star change over the last 7 days
- #149
GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.
★ 589+4Star change over the last 7 days - #150★ 579+0Star change over the last 7 days