A-to-Z Bug Bounty Hunting Tools
☆135Mar 26, 2025Updated last year
Alternatives and similar repositories for BugBountyTools
Users that are interested in BugBountyTools are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This is my personal Enumeration Handbook that I used for the OSCP 2023☆26Aug 21, 2023Updated 3 years ago
- Burp Suite extension — passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, ent…☆46May 15, 2026Updated 3 months ago
- Active Directory share enumeration tool☆13Apr 28, 2025Updated last year
- XSSRecon automates the process of testing URL parameters for reflection of a test payload rix4uni and further checks how special characte…☆55Aug 11, 2026Updated last week
- bug bounty automation with 4-phase workflow: passive OSINT, active recon, intelligent analysis, and systematic vulnerability testing (XSS…☆23Nov 4, 2025Updated 9 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 5 months ago
- The Complete Guide to Dorking for Bug Bounty Hunters☆22Jan 1, 2026Updated 7 months ago
- ☆24Jan 20, 2026Updated 7 months ago
- Community curated list of templates for the nuclei engine to find security vulnerabilities.☆109Nov 24, 2025Updated 8 months ago
- Widget Options – The #1 WordPress Widget & Block Control Plugin <= 4.0.7 - Authenticated (Contributor+) Remote Code Execution☆13Dec 2, 2024Updated last year
- Templtor is a bash script that will gather all the community Nuclei templates.☆41Dec 19, 2025Updated 8 months ago
- ☆31Jun 26, 2026Updated last month
- ☆18Jul 16, 2025Updated last year
- Active Directory forensic framework☆16May 18, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Interactive XSS Labs to get into Client-Side Hacking☆96Feb 25, 2026Updated 5 months ago
- ☆11Dec 27, 2024Updated last year
- OpenRedirector is a powerful automation tool for detecting Open Redirect vulnerabilities in web applications☆21Oct 30, 2025Updated 9 months ago
- Open-source unified security operations & threat intelligence platform for OT/ICS environments with ontology-driven dashboards☆48May 27, 2026Updated 2 months ago
- Live runtime audit for installed Android apps. Runs on the rooted phone, serves a browser dashboard.☆31May 23, 2026Updated 3 months ago
- Find XSS payloads that actually work by filtering them based on real-world constraints instead of blind payload spraying.☆282Aug 12, 2026Updated last week
- Android APK security analysis tool. Decompiles DEX, scans for vulns, parses manifests and certs. Runs in your browser.☆70May 14, 2026Updated 3 months ago
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information i…☆17Apr 13, 2026Updated 4 months ago
- A thin Python wrapper around netexec (nxc) that runs the same target/credential pair across many nxc protocols in a single command, with …☆18May 10, 2026Updated 3 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite☆90Updated this week
- Google Dorks and keywords for bug hunters.☆17Aug 16, 2021Updated 5 years ago
- ☆16Jun 28, 2025Updated last year
- Bug Bounty Methodology☆334Aug 4, 2026Updated 2 weeks ago
- AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude…☆4,391Updated this week
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆34May 28, 2026Updated 2 months ago
- A powerful URL parameter and request fuzzing tool that processes URLs or Burp Suite raw requests, replacing values with custom payloads w…☆21Apr 12, 2026Updated 4 months ago
- ☆27Aug 19, 2024Updated 2 years ago
- Free BugBounty KrazePlanetTraining☆60Dec 17, 2025Updated 8 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- This project is an Automated Penetration Testing and Vulnerability Scanning Framework. It is designed to all-in-one automated handles eve…☆21Jun 15, 2026Updated 2 months ago
- Collected resources for OSWA preparation.☆28Jan 25, 2023Updated 3 years ago
- XSS payloads to bypass various XSS filters☆15May 1, 2019Updated 7 years ago
- ⚔️ Community maintained directory, MCP and API of 3,000+ active bug bounty programs and VDPs☆400Updated this week
- ☆15Jan 4, 2021Updated 5 years ago
- ☆166Jun 1, 2025Updated last year
- JWTLens - Burp Suite extension for automated JWT security testing. 62 checks: passive scanning, algorithm confusion, signature bypass, …☆55Mar 19, 2026Updated 5 months ago