All Categories → Software Quality → bug-bounty

Top 75 bug-bounty open source projects

Scant3r
ScanT3r - Web Security Scanner
Diodata
Tools, data, and contact lists relevant to The disclose.io Project.
✭ 232
bug-bounty
Hawkeye
Hawkeye filesystem analysis tool
Awesome Bbht
A bash script that will automatically install a list of bug hunting tools that I find interesting for recon, exploitation, etc. (minus burp) For Ubuntu/Debain.
Di.we.h
Repositório com conteúdo sobre web hacking em português
Axiom
The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
Bbr
An open source tool to aid in command line driven generation of bug bounty reports based on user provided templates.
Pidrila
Python Interactive Deepweb-oriented Rapid Intelligent Link Analyzer
Goaltdns
A permutation generation tool written in golang
Facebook Bugbounty Writeups
Collection of Facebook Bug Bounty Writeups
Awesome Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
Not Your Average Web Crawler
A web crawler (for bug hunting) that gathers more than you can imagine.
Subtake
Automatic finder for subdomains vulnerable to takeover. Written in Go, based on @haccer's subjack.
Keye
Keye is a reconnaissance tool that was written in Python with SQLite3 integrated. After adding a single URL, or a list of URLs, it will make a request to these URLs and try to detect changes based on their response's body length.
Ecommerce Website Security Checklist
List of considerations for commerce site auditing and security teams. This is summary of action points and areas that need to be built into the Techinical Specific Document, or will be checked in the Security testing phases.
Subjack
Subdomain Takeover tool written in Go
Clickjacking Tester
A python script designed to check if the website if vulnerable of clickjacking and create a poc
Spellbook
Micro-framework for rapid development of reusable security tools
Ssrfmap
Simple Server Side Request Forgery services enumeration tool.
Brokenlinkhijacker
A Fast Broken Link Hijacker Tool written in Python
31 Days Of Api Security Tips
This challenge is Inon Shkedy's 31 days API Security Tips.
Burpbounty
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
Subdomainizer
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.
Sublert
Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.
Swiftnessx
A cross-platform note-taking & target-tracking app for penetration testers.
Diodb
Open-source vulnerability disclosure and bug bounty program database.
Subover
A Powerful Subdomain Takeover Tool
Awesome Oneliner Bugbounty
A collection of awesome one-liner scripts especially for bug bounty tips.
Git Hound
Reconnaissance tool for GitHub code search. Finds exposed API keys using pattern matching, commit history searching, and a unique result scoring system.
Security Tools
Collection of small security tools, mostly in Bash and Python. CTFs, Bug Bounty and other stuff.
Subfinder
Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing.
Black Hat Rust
Applied offensive security with Rust - Early access - https://academy.kerkour.com/black-hat-rust?coupon=GITHUB
Offensive Docker
Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.
Injuredandroid
A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.
Vajra
Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple target during web applications penetration testing.
Awesome Hacking Lists
平常看到好的渗透hacking工具和多领域效率工具的集合
Srcms
SRCMS企业应急响应与缺陷管理系统
Dumpall
一款信息泄漏利用工具,适用于.git/.svn源代码泄漏和.DS_Store泄漏
Rengine
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with…
awesome-blockchain-bug-bounty
A comprehensive curated list of available Blockchain Bug Bounty Programs.
swiss-bugbounty-programs
List of bug bounty and coordinated vulnerability disclosure programs of companies/organisations in Switzerland
Bucket-Flaws
Bucket Flaws ( S3 Bucket Mass Scanner ): A Simple Lightweight Script to Check for Common S3 Bucket Misconfigurations
SQLi-Query-Tampering
SQLi Query Tampering extends and adds custom Payload Generator/Processor in Burp Suite's Intruder. This extension gives you the flexibility of manual testing with many powerful evasion techniques.
viewstamped-replication-made-famous
A $20k consensus challenge based on TigerBeetle's implementation of the pioneering Viewstamped Replication protocol.
1-60 of 75 bug-bounty projects