Top #bugbounty Tools & Software
Explore 23 hand-picked tools and software tagged with bugbounty โ ranked by popularity and community signals.
PayloadsAllTheThings
githubA list of useful payloads and bypass for Web Application Security and Pentest/CTF
dirsearch
githubWeb path scanner
nuclei-templates
githubCommunity curated list of templates for the nuclei engine to find security vulnerabilities.
awesome-hacker-search-engines
githubA curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
Sn1per
githubAttack Surface Management Platform
bbot
githubThe recursive internet scanner for hackers. ๐งก
wstg
githubThe Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
reconftw
githubreconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
AllAboutBugBounty
githubAll about bug bounty (bypasses, payloads, and etc)
bugbounty-cheatsheet
githubA list of interesting payloads, tips and tricks for bug bounty hunters.
osmedeus
githubA Modern Orchestration Engine for Security
hackerone-reports
githubTop disclosed reports from HackerOne
can-i-take-over-xyz
github"Can I take over XYZ?" โ a list of services and how to claim (sub)domains with dangling DNS records.
dalfox
github๐๐ฆ Dalfox is a powerful open-source XSS scanner and utility focused on automation.
WebHackersWeapons
githubโ๏ธ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting
interactsh
githubAn OOB interaction gathering server and client library
knockpy
githubKnock Subdomain Scan
Fuzzing101
githubAn step by step fuzzing tutorial. A GitHub Security Lab initiative
vulnerability-Checklist
githubThis repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter
cariddi
githubTake a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
pentest-tools
githubA collection of custom security tools for quick needs.
caido
github๐ Caido releases, wiki and roadmap
31-days-of-API-Security-Tips
githubThis challenge is Inon Shkedy's 31 days API Security Tips.