A list of resources for those interested in getting started in bug bounties
-
Updated
Jul 23, 2024
A list of resources for those interested in getting started in bug bounties
Open-source vulnerability disclosure and bug bounty program database
BUG BOUNTY WRITEUPS - OWASP TOP 10 🔴🔴🔴🔴✔
Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.
Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist
An open source tool to aid in command line driven generation of bug bounty reports based on user provided templates.
A Collection of Notes, Methodologies, POCs and everything else related to Bug Hunting.
This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.
A handy plugin for copying requests/responses directly from Burp, some extra magic included.
bug bounty
This repo is for people that are searching for IT Security Specialists in their native language, or for people that are language learners and just want to immerse more!
A handy tool for bug bounty hunters/pentesters to check the http status codes of all the links/URLs collectively
domainghost by b0dj0x
A local-first AppSec and bug bounty workspace that combines reconnaissance, endpoint discovery, vulnerability scanning, screenshots, evidence tracking, and reporting through a unified dashboard.
All-in-one Dockerized recon toolkit for security researchers — combines Subfinder, Sublist3r, MassDNS, dnsx, Assetfinder, and Nmap for comprehensive domain and subdomain intelligence gathering.
A highly automated and modular bug bounty reconnaissance toolkit integrating over 15 industry-standard tools for streamlined subdomain enumeration, vulnerability detection, and OSINT gathering. Designed for efficiency, scalability, and precision in real-world security assessments.
Endpoint fuzzing, method checks, authentication probes, and JSON-aware reporting.
Advanced XSS vulnerability scanner using Selenium and real browser execution verification for authorized security testing and bug bounty research.
Burp Suite extension for automated multi-tenant IDOR/BOLA testing
A powerful terminal based automated reconnaissance framework for bug bounty hunters. Wraps 14+ industry standard tools for subdomain enum, port scanning, OSINT, JS analysis, cloud recon & more. Hunt the target. Leave no stone unturned.
Add a description, image, and links to the bug-bounty-hunters topic page so that developers can more easily learn about it.
To associate your repository with the bug-bounty-hunters topic, visit your repo's landing page and select "manage topics."