bughuntercat's Stars
djadmin/awesome-bug-bounty
A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.
roglew/guppy-proxy
The Guppy Proxy (GUI Pappy)
Hack-with-Github/Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
juice-shop/juice-shop
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
smlinux/rtl8723de
Realtek RTL8723DE module for Linux
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
sleuthkit/autopsy
Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card.
gwen001/BB-datas
Tools and datas related to Bug Bounty.
secdec/attack-surface-detector-zap
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
mystech7/Burp-Hunter
XSS Hunter Burp Plugin
tomnomnom/hacks
A collection of hacks and one-off scripts
LewisArdern/bXSS
bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.
zaproxy/zaproxy
The ZAP by Checkmarx Core project
Fuzzapi/fuzzapi
Fuzzapi is a tool used for REST API pentesting and uses API_Fuzzer gem
bugcrowd/bugcrowd_university
Open source education content for the researcher community
tarunkant/EndPoint-Finder
Finds the End-Points in JavaScript files
rapid7/metasploitable3
Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.
sensepost/gowitness
🔍 gowitness - a golang, web screenshot utility using Chrome Headless
secdec/attack-surface-detector-burp
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
secfigo/Awesome-Fuzzing
A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.
evilsocket/dirsearch
A Go implementation of dirsearch.
wagiro/BurpBounty
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
bjut-hz/E-Books
IT e-books
golang/go
The Go programming language
TechBookHunter/Free-Python-Books
A curated collection of free eBooks about Python
projectdiscovery/subfinder
Fast passive subdomain enumeration tool.
1N3/IntruderPayloads
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
rinetd/burpsuite
zaproxy/zap-extensions
ZAP Add-ons
bugcrowd/vulnerability-rating-taxonomy
Bugcrowd’s baseline priority ratings for common security vulnerabilities