A list of resources for those interested in getting started in bug bounties
-
Updated
Jul 23, 2024
A list of resources for those interested in getting started in bug bounties
Open-source vulnerability disclosure and bug bounty program database
BUG BOUNTY WRITEUPS - OWASP TOP 10 🔴🔴🔴🔴✔
Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.
Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist
An open source tool to aid in command line driven generation of bug bounty reports based on user provided templates.
A Collection of Notes, Methodologies, POCs and everything else related to Bug Hunting.
This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.
A handy plugin for copying requests/responses directly from Burp, some extra magic included.
bug bounty
This repo is for people that are searching for IT Security Specialists in their native language, or for people that are language learners and just want to immerse more!
A handy tool for bug bounty hunters/pentesters to check the http status codes of all the links/URLs collectively
domainghost by b0dj0x
A local-first AppSec and bug bounty workspace that combines reconnaissance, endpoint discovery, vulnerability scanning, screenshots, evidence tracking, and reporting through a unified dashboard.
Automated web security testing tool designed to detect Insecure Direct Object References (IDOR) vulnerabilities in web applications
DNScope is an advanced DNS attack-surface intelligence toolkit for security research and authorized bug bounty testing. Analyze DNS records, DNSSEC, email security, subdomains, certificates, RDAP, IP/ASN, cloud infrastructure, threat intelligence, historical changes, monitoring, and reports.
A highly automated and modular bug bounty reconnaissance toolkit integrating over 15 industry-standard tools for streamlined subdomain enumeration, vulnerability detection, and OSINT gathering. Designed for efficiency, scalability, and precision in real-world security assessments.
All-in-one Dockerized recon toolkit for security researchers — combines Subfinder, Sublist3r, MassDNS, dnsx, Assetfinder, and Nmap for comprehensive domain and subdomain intelligence gathering.
XSS Injection Scanner is an automated security testing tool designed to detect Cross-Site Scripting (XSS) vulnerabilities in web applications
Advanced XSS vulnerability scanner using Selenium and real browser execution verification for authorized security testing and bug bounty research.
To associate your repository with the bug-bounty-hunters topic, visit your repo's landing page and select "manage topics."