bug-bounty
There are 647 repositories under bug-bounty topic.
resolvers
The most exhaustive list of reliable DNS resolvers.
offensive-docker
Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.
socialhunter
crawls the website and finds broken social media links that can be hijacked
ipranges
🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), OpenAI (GPTBot) and other with daily updates.
vajra
Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple target during web applications penetration testing.
penetration-testing-cheat-sheet
Work in progress...
InjuredAndroid
A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.
scant3r
ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )
misconfig-mapper
Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!
Facebook-BugBounty-Writeups
Collection of Facebook Bug Bounty Writeups
SQLiDetector
Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.
goop
Yet another tool to dump a git repository from a website, focused on as-complete-as-possible dumps and handling weird edge-cases.
xurlfind3r
A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directly with the target but instead gathers data that is already publicly available.
rfi-lfi-payload-list
🎯 RFI/LFI Payload List
awesome-bbht
A bash script that will automatically install a list of bug hunting tools that I find interesting for recon, exploitation, etc. (minus burp) For Ubuntu/Debain.
rustbuster
A Comprehensive Web Fuzzer and Content Discovery Tool
revsuit
RevSuit is a flexible and powerful reverse connection platform designed for receiving connection from target host in penetration.
ppmap
A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.
wifi-penetration-testing-cheat-sheet
Work in progress...
reaper
💀 Don't fear the Reaper 👻
gotator
Gotator is a tool to generate DNS wordlists through permutations.
rekono
Pentesting automation platform that combines hacking tools to complete assessments
DirDar
DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it
reconmap
Vulnerability assessment and penetration testing automation and reporting platform for teams.
awesome-rtc-hacking
a list of awesome resources related to security and hacking of VoIP, WebRTC and VoLTE
exifLooter
ExifLooter finds geolocation on all image urls and directories also integrates with OpenStreetMap
cheat-sheets
A list of cheat sheets for application security
xss_vibes
A modern tool written in Python that automates your xss findings.
hysp
📦 An independent package manager that every hacker deserves.
Bug-Bounty
Bug Bounty ~ Awesomes | Books | Cheatsheets | Checklists | Tools | Wordlists | More
android-penetration-testing-cheat-sheet
Work in progress...
ax
The Distributed Scanning Framework for Everybody! Control Your Infrastructure, Scale Your Scanning—On Your Terms. Easily distribute arbitrary binaries and scripts using any of our eight supported cloud providers!
lit-bb-hack-tools
Little Bug Bounty & Hacking Tools⚔️
missing-cve-nuclei-templates
Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and vulnerability assessments too.
sub404
A python tool to check subdomain takeover vulnerability
ios-penetration-testing-cheat-sheet
Work in progress...