How To approach recon on real targets — from passive enumeration to origin IP discovery. Covers tools, automation, and the logic behind each phase.
☆402Jul 5, 2026Updated 2 months ago
Alternatives and similar repositories for Full-Bug-Bounty-Hunting-Methodology-2026
Users that are interested in Full-Bug-Bounty-Hunting-Methodology-2026 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full writ…☆1,257Sep 1, 2026Updated last week
- Bug Bounty Methodology☆335Aug 4, 2026Updated last month
- ☆79May 5, 2025Updated last year
- AI-powered bug bounty hunting toolkit that works with or without subscription.☆4,750Sep 4, 2026Updated last week
- A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report…☆362Aug 24, 2026Updated 2 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- My Main App Hacking CheckList☆35Jun 20, 2026Updated 2 months ago
- AI-Powered Agents for Bub-Bounty Pentesting and Red-Teaming purposes☆417Apr 30, 2026Updated 4 months ago
- Collection of documentation, tools, and tips related to vulnerability research.☆265Sep 5, 2026Updated last week
- Here's an updated Google Dorking list for 2025 Bug Bounty Hunting, incorporating new patterns and, the latest trends.☆21Apr 26, 2025Updated last year
- ☆115Mar 30, 2026Updated 5 months ago
- Agentic offensive-security in your terminal☆1,346Aug 31, 2026Updated last week
- A resources for who want to learn and get deep into client-side bugs☆558Dec 8, 2024Updated last year
- Many script that can be modified according to your needs for Information Gathering and Asset discovery in Bug Bounty Hunting (Pull reques…☆62Feb 26, 2024Updated 2 years ago
- Apkx-Hunter is an Android Static Analysis Framework in Debian Package written entirely in C with OWASP MASVS scanning with 15 categories …☆92Sep 1, 2026Updated last week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Solutions for all the WebSecurityAcademy with Videos☆130Aug 3, 2026Updated last month
- A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curat…☆4,450Updated this week
- Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier☆244Jul 7, 2026Updated 2 months ago
- ☆96May 11, 2026Updated 4 months ago
- A OWASP Based Checklist With 80+ Test Cases☆206Oct 26, 2022Updated 3 years ago
- A shellcode loader generator with support for multiple injection techniques, built for red team engagements.☆101Jul 1, 2026Updated 2 months ago
- List of AI Hacking Agents☆662Aug 29, 2026Updated 2 weeks ago
- An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, and GenAI…☆312Aug 10, 2026Updated last month
- Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engage…☆2,222Aug 16, 2026Updated 3 weeks ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Bug bounty focused JavaScript security analysis for crawling web assets, source maps, and secret discovery☆65Aug 1, 2026Updated last month
- BountyLens MCP server — connect Claude Code to your Hunter Tracker☆64Jun 22, 2026Updated 2 months ago
- ☆264Dec 10, 2025Updated 9 months ago
- A personal RAG system for offensive security knowledge☆178Aug 11, 2026Updated last month
- All-round bug bounty skill for Claude Code parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, an…☆418Aug 29, 2026Updated 2 weeks ago
- AutoAR is an automated security reconnaissance tool, ASM and Discord bot for bug bounty hunters and penetration testers. It automates gat…☆248Aug 18, 2026Updated 3 weeks ago
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆61Jul 12, 2026Updated 2 months ago
- autonomous red teaming platform; multi-agent offensive-security meta-harness☆6,102Updated this week
- My ATO Via Password Reset Methodology☆54May 13, 2026Updated 3 months ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian☆322Sep 1, 2026Updated last week
- A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk sco…☆207Updated this week
- Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | …☆2,094Updated this week
- My Private Bug Hunting Methodology☆450Nov 27, 2024Updated last year
- 0xJS is an AI-powered JavaScript Security Tool☆67Apr 16, 2026Updated 4 months ago
- claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md f…☆3,593Aug 30, 2026Updated last week
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods☆26Jul 15, 2026Updated last month