All Projects → BugBountyResources → Resources

BugBountyResources / Resources

A Storehouse of resources related to Bug Bounty Hunting collected from different sources. Latest guides, tools, methodology, platforms tips, and tricks curated by us.

Projects that are alternatives of or similar to Resources

Crithit
Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to cross-check vulnerabilities over multiple hosts.
Stars: ✭ 182 (+193.55%)
Mutual labels:  hacking, security-tools, pentesting, penetration-testing, infosec, security-audit, security-vulnerability, bugbounty
Security Tools
Collection of small security tools, mostly in Bash and Python. CTFs, Bug Bounty and other stuff.
Stars: ✭ 509 (+720.97%)
Mutual labels:  hacking, security-tools, pentesting, infosec, security-testing, bugbounty
Habu
Hacking Toolkit
Stars: ✭ 635 (+924.19%)
Mutual labels:  hacking, security-tools, pentesting, penetration-testing, security-audit, security-testing
Vhostscan
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
Stars: ✭ 767 (+1137.1%)
Mutual labels:  hacking, security-tools, penetration-testing, security-audit, bugbounty
Hosthunter
HostHunter a recon tool for discovering hostnames using OSINT techniques.
Stars: ✭ 427 (+588.71%)
Mutual labels:  hacking, security-tools, pentesting, penetration-testing, bugbounty
Rengine
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with…
Stars: ✭ 3,439 (+5446.77%)
Mutual labels:  security-tools, penetration-testing, infosec, pentesting, bugbounty
Minesweeper
A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).
Stars: ✭ 162 (+161.29%)
Mutual labels:  hacking, security-tools, penetration-testing, security-audit, bugbounty
Nosqlmap
Automated NoSQL database enumeration and web application exploitation tool.
Stars: ✭ 1,928 (+3009.68%)
Mutual labels:  hacking, security-tools, penetration-testing, security-audit, bugbounty
Awesome Shodan Queries
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩‍💻
Stars: ✭ 2,758 (+4348.39%)
Mutual labels:  hacking, security-tools, pentesting, penetration-testing, infosec
Cameradar
Cameradar hacks its way into RTSP videosurveillance cameras
Stars: ✭ 2,775 (+4375.81%)
Mutual labels:  hacking, security-tools, pentesting, penetration-testing, infosec
Cheatsheet God
Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
Stars: ✭ 3,521 (+5579.03%)
Mutual labels:  hacking, security-tools, pentesting, penetration-testing, security-vulnerability
Awesome Mobile Security
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
Stars: ✭ 1,837 (+2862.9%)
Mutual labels:  resources, hacking, security-tools, pentesting, bugbounty
Dirsearch
Web path scanner
Stars: ✭ 7,246 (+11587.1%)
Mutual labels:  hacking, pentesting, penetration-testing, infosec, bugbounty
Archstrike
An Arch Linux repository for security professionals and enthusiasts. Done the Arch Way and optimized for i686, x86_64, ARMv6, ARMv7 and ARMv8.
Stars: ✭ 401 (+546.77%)
Mutual labels:  hacking, pentesting, penetration-testing, security-audit
Diamorphine
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64)
Stars: ✭ 725 (+1069.35%)
Mutual labels:  hacking, security-tools, pentesting, security-audit
Nmap
Idiomatic nmap library for go developers
Stars: ✭ 391 (+530.65%)
Mutual labels:  hacking, pentesting, penetration-testing, infosec
Pentesting Bible
Learn ethical hacking.Learn about reconnaissance,windows/linux hacking,attacking web technologies,and pen testing wireless networks.Resources for learning malware analysis and reverse engineering.
Stars: ✭ 8,981 (+14385.48%)
Mutual labels:  resources, hacking, pentesting, bugbounty
Interlace
Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.
Stars: ✭ 760 (+1125.81%)
Mutual labels:  hacking, security-tools, penetration-testing, bugbounty
Dumpsterfire
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
Stars: ✭ 775 (+1150%)
Mutual labels:  hacking, security-tools, pentesting, infosec
A Red Teamer Diaries
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
Stars: ✭ 382 (+516.13%)
Mutual labels:  hacking, security-tools, pentesting, penetration-testing

BBR

Come chat with us!

Bug Bounty Resources

Storehouse of resources related to Bug Bounty Hunting collected from different sources. Watch and Star this repo for all latest guides, tools, methodology, platforms tips, and tricks curated by us.

Getting Started (in Bug Hunting and More...)

Coming Soon, till then, just keep watching or, 🌟 (starring) us! Thanks for your patience.

Bug Bounty Platforms

List of Top Platforms (Open/Public)

  • Hackerone (H1)

  • BugCrowd (BC)

  • Intigriti

  • BountyGraph (Software dependencies) [Closing on 12th December, 2018]

  • BountyFactory

  • OpenBugBounty (OBB) [Limited to XSSi and other non-intrusive type vulnerabilities]

List of Top (Closed/Invite-only) Platforms

  • Synack

  • Cobalt

  • Zerocopter

  • Detectify

Upcoming Platforms

Have an insider edge over the newer platforms, be the first to join them!

  • PlugBounty (Vulnerabilities in Plugins)

  • BugsBounty (Indian origin)

Misc. Other Platforms (Open)

  • Hackenproof

  • BugBountyjp (dubious - Payment Delays, Unresponsive)

  • BugsBounty (Upcoming Platform, currently running Internally and exclusively)

  • CESPPA

  • Hackrfi

  • Safehats (Indian origin, although registration is open, goes through validation)

  • Hacktrophy

  • Cyberarmy.id (Indonesian Origin)

  • FireBounty (collection/list of bug bounty programs on different platforms like hackerone, bugcrowd, etc.)

Misc. other (Invite-only/closed) Platforms

  • BugBountyZone

  • Federacy

  • Yogosha

  • Vulnscope

  • Antihack (dubious/infamous for non-payments, and other issues)

A word of caution goes here, we don't endorse or, opine about any platforms and the comments about them in parentheses merely reflect unbiased information which we gathered from the community and other credible sources. Platforms marked dubious, have payment delays and issues, so care should be taken while working on them.

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].