A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report templates, CVE/CWE watchlists, and a local VM practice lab. Built for disciplined, ethical hunting.
☆336Jul 20, 2026Updated last month
Alternatives and similar repositories for bugbounty-lab101
Users that are interested in bugbounty-lab101 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆1,289Aug 11, 2026Updated last week
- How To approach recon on real targets — from passive enumeration to origin IP discovery. Covers tools, automation, and the logic behind e…☆385Jul 5, 2026Updated last month
- Autonomous red teaming and evidence-backed security evaluation for live AI agents.☆28Jul 22, 2026Updated last month
- An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, and GenAI…☆298Aug 10, 2026Updated last week
- A personal RAG system for offensive security knowledge☆176Aug 11, 2026Updated last week
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian☆278Updated this week
- 🦞 Local, read-only security scanner for OpenClaw. Finds config, prompt-injection and supply-chain risks — A–F grade.☆59Aug 8, 2026Updated 2 weeks ago
- PenTest and BugBounty 🕵️☆16Updated this week
- Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full writ…☆1,188Jul 31, 2026Updated 3 weeks ago
- GitHub-native command-and-control framework for authorized security research, with encrypted multi-channel transport and resilient failov…☆223Jul 18, 2026Updated last month
- A blazingly fast, multi-threaded TUI malware analysis tool built in Rust. Features deep PE parsing, YARA scanning, and heuristic risk sco…☆204Aug 16, 2026Updated last week
- HackAgent is an open-source security toolkit to detect vulnerabilities of your AI Agents☆364Aug 15, 2026Updated last week
- ☆112Mar 30, 2026Updated 4 months ago
- Agentic offensive-security in your terminal☆1,303Jun 14, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Bug Bounty Methodology☆334Aug 4, 2026Updated 2 weeks ago
- AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude…☆4,391Updated this week
- Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can repla…☆1,614Updated this week
- Python Exploitation Framework, V8 Engine Debugger, Proxy interceptor, marketplace, post-exploitation, backdoor generator,....☆607Updated this week
- Codex CLI jailbreak guide — customizing system prompt via model_instructions_file config☆191Jul 3, 2026Updated last month
- Stealth hybrid URL mapper☆31May 1, 2026Updated 3 months ago
- A live, browser-based threat intelligence dashboard aggregating 68 curated sources across government advisories, news, research, vendor b…☆16Updated this week
- 66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, e…☆312Aug 11, 2026Updated last week
- AutoAR is an automated security reconnaissance tool, ASM and Discord bot for bug bounty hunters and penetration testers. It automates gat…☆243Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆13Mar 6, 2025Updated last year
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆34May 28, 2026Updated 2 months ago
- ☆15Feb 27, 2026Updated 5 months ago
- powerfull pentesting tool to checking email by smtp command☆10Feb 29, 2024Updated 2 years ago
- 安全研究工作台,集成逆向工程、CTF、移动安全、Web安全于一体☆196Aug 3, 2026Updated 2 weeks ago
- ☆1,619Mar 7, 2026Updated 5 months ago
- List of AI Hacking Agents☆643Aug 10, 2026Updated last week
- autonomous red teaming platform; multi-agent offensive-security meta-harness☆5,647Aug 12, 2026Updated last week
- claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md f…☆2,950May 8, 2026Updated 3 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools…☆806Jun 12, 2026Updated 2 months ago
- AI 驱动的红队免杀知识库 — AI-generated red team evasion notes☆59Jun 23, 2026Updated 2 months ago
- Dump Linux keyrings☆24Jul 15, 2024Updated 2 years ago
- A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curat…☆3,745Updated this week
- Intentionally Vulnerable Hacking Labs☆595Aug 12, 2026Updated last week
- A BugBounty playbook covering vulnerability bypasses, payloads, and quick checks for OWASP Top 10 + extras.☆23Sep 29, 2025Updated 10 months ago
- A Chrome extension that watches your HackerOne reports and alerts you when their status changes. Its main reason to exist is internal act…☆15Jul 3, 2026Updated last month