There are 187 repositories under bug-bounty topic.
A collection of various awesome lists for hackers, pentesters and security researchers
Web path scanner
A list of resources for those interested in getting started in bug bounties
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
Applied offensive security with Rust - https://kerkour.com/black-hat-rust
A collection of awesome one-liner scripts especially for bug bounty tips.
This challenge is Inon Shkedy's 31 days API Security Tips.
Collection of quality safety articles. Awesome articles.
🕵️ OSINT Tools for gathering information and actions forensics 🕵️
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
API Security Project aims to present unique attack & defense methods in API Security field
A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities.
A collection of one-liners for bug bounty hunting.
🦄 🦄 🦄 Peripheral smart contracts for interacting with Uniswap v3
🎯 XML External Entity (XXE) Injection Payload List
Obtain GraphQL API schema even if the introspection is disabled
An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.
平常看到好的渗透hacking工具和多领域效率工具的集合
Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.
A Powerful Subdomain Takeover Tool
A cross-platform note-taking & target-tracking app for penetration testers.
My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.
BUG BOUNTY WRITEUPS - OWASP TOP 10 🔴🔴🔴🔴✔
Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text