Skip to main content
buildradar
Sign in
Topic · bugbounty

bugbounty

Tracked open-source repos tagged bugbounty, sorted by stars.

157 repos
  • A curated list of Smart Contract Security materials and resources For Researchers

    905-1Star change over the last 7 days
  • These are my checklists which I use during my hunting.

    894+3Star change over the last 7 days
  • getJS@003random

    A tool to fastly get all javascript sources/files

    893+3Star change over the last 7 days
  • netlas-cookbook@netlas-io

    The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of Netlas.io.

    888-1Star change over the last 7 days
  • apk2url@n0mi1k

    An OSINT tool to quickly extract IP and URL endpoints from APKs by disassembling and decompiling

    874-1Star change over the last 7 days
  • Collection of Facebook Bug Bounty Writeups

    845+0Star change over the last 7 days
  • censys-subdomain-finder@christophetd

    ⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.

    843-2Star change over the last 7 days
  • An insane list of all dorks taken from everywhere from various different sources.

    824-1Star change over the last 7 days
  • ShadowClone@fyoorer

    Unleash the power of cloud

    822+1Star change over the last 7 days
  • Garud@R0X4R

    An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.

    811+1Star change over the last 7 days
  • Subdominator@RevoltSecurities

    SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty

    809+1Star change over the last 7 days
  • Web_Hacking@Mehdi0x90

    Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.

    806+2Star change over the last 7 days
  • emploleaks@infobyte

    An OSINT tool that helps detect members of a company with leaked credentials

    791+0Star change over the last 7 days
  • CyberPhish@Cyber-Dioxide

    A heavily armed customizable phishing tool for educational purpose only

    735+1Star change over the last 7 days
  • TOP@GhostTroops

    TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things

    733+1Star change over the last 7 days
  • 🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️

    732+0Star change over the last 7 days
  • keyFinder@momenbasel

    Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

    707+2Star change over the last 7 days
  • GDorks@Ishanoshada

    Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories ) + Web App

    705+2Star change over the last 7 days
  • chiasmodon@chiasmod0n

    Chiasmodon is an OSINT tool designed to assist in the process of gathering information about a target domain. Its primary functionality revolves around searching for domain-related data, including domain emails, domain credentials, CIDRs , ASNs , and subdomains, the tool also allows users to search Google Play application ID.

    698+1Star change over the last 7 days
  • docem@whitel1st

    A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)

    689+1Star change over the last 7 days
  • scant3r@MindPatch

    ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )

    684-2Star change over the last 7 days
  • ppfuzz@dwisiswant0

    A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀

    676+1Star change over the last 7 days
  • Bug-Bounty@AnLoMinus

    Bug Bounty ~ Awesomes | Books | Cheatsheets | Checklists | Tools | Wordlists | More

    663+3Star change over the last 7 days
  • SQLiDetector@eslam3kl

    Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.

    644+4Star change over the last 7 days
  • arsenal-ng@halilkirazkaya

    The classic launcher, evolved. Fast, Go-based command library equipped with 200+ cybersecurity cheat-sheets. Just install and start hacking.

    634+9Star change over the last 7 days
  • Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.

    630+2Star change over the last 7 days
  • AutorizePro@WuliRuler

    🧿 AutorizePro是一款强大越权检测 Burp 插件,通过增加 AI 辅助分析 && 进一步优化检测逻辑,大幅降低误报率,提升越权漏洞检出效率。 [ AutorizePro is a authorization enforcement detection extension for burp suite. By adding Ai-assisted analysis, it significantly reduces the false positive rate and improves the efficiency of vulnerability detection.

    614+3Star change over the last 7 days
  • leaker@vflame6

    Passive leak enumeration tool.

    594+2Star change over the last 7 days
  • gato-x@AdnaneKhan

    GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.

    589+4Star change over the last 7 days
  • webHunt@ghsec

    Web App bug hunting

    579+0Star change over the last 7 days
← Back to topics