There are 359 repositories under bugbounty topic.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Web path scanner
A list of resources for those interested in getting started in bug bounties
Fast passive subdomain enumeration tool.
Community curated list of templates for the nuclei engine to find security vulnerabilities.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
A list of interesting payloads, tips and tricks for bug bounty hunters.
httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
All about bug bounty (bypasses, payloads, and etc)
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
Automated All-in-One OS Command Injection Exploitation Tool.
Scanning APK file for URIs, endpoints & secrets.
Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application
ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。
A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
🎯 SQL Injection Payload List
A collection of custom security tools for quick needs.
⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting
🌙🦊 DalFox is an powerful open source XSS scanning tool and parameter analyzer, utility
A curated list of various bug bounty tools
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
Penetration tests guide based on OWASP including test cases, resources and examples.
pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching
💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh