Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Onelinetips and explain the commands, for the better understanding of new hunters..
☆5,223Jan 31, 2026Updated last month
Alternatives and similar repositories for KingOfBugBountyTips
Users that are interested in KingOfBugBountyTips are comparing it to the libraries listed below
Sorting:
- A collection of awesome one-liner scripts especially for bug bounty tips.☆3,077Jul 29, 2024Updated last year
- Collection of methodology and test case for various web vulnerabilities.☆7,039Jun 25, 2025Updated 8 months ago
- All about bug bounty (bypasses, payloads, and etc)☆6,658Sep 8, 2023Updated 2 years ago
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.☆6,082Aug 14, 2024Updated last year
- BBT - Bug Bounty Tools (examples💡)☆1,883Apr 5, 2024Updated last year
- A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference☆5,551Aug 6, 2023Updated 2 years ago
- This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for …☆3,659Updated this week
- reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and findin…☆7,280Updated this week
- A list of interesting payloads, tips and tricks for bug bounty hunters.☆6,382Sep 14, 2023Updated 2 years ago
- 🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.☆4,859Feb 28, 2026Updated last week
- Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing☆3,012Jun 24, 2024Updated last year
- The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, f…☆4,352Sep 30, 2024Updated last year
- GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep☆1,401Sep 13, 2024Updated last year
- A collection of hacks and one-off scripts☆2,423Mar 13, 2025Updated 11 months ago
- Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.☆4,842Jan 1, 2025Updated last year
- Rockyou for web fuzzing☆3,028Feb 11, 2026Updated 3 weeks ago
- A list of resources for those interested in getting started in bug bounties☆11,867Jul 23, 2024Updated last year
- HTTP parameter discovery suite.☆6,109Feb 20, 2025Updated last year
- reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via E…☆8,497Nov 16, 2025Updated 3 months ago
- Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application☆5,000Dec 21, 2024Updated last year
- declutters url lists for crawling/pentesting☆1,531Feb 23, 2025Updated last year
- Automation for javascript recon in bug bounty.☆1,069Sep 9, 2023Updated 2 years ago
- A python script that finds endpoints in JavaScript files☆4,294Apr 13, 2024Updated last year
- Hidden parameters discovery suite☆2,028Sep 8, 2024Updated last year
- For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙☆1,820Jun 9, 2024Updated last year
- The Swiss Army knife for automated Web Application Testing☆2,323May 8, 2024Updated last year
- A repository that includes all the important wordlists used while bug hunting.☆1,379Mar 11, 2023Updated 2 years ago
- SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files☆2,392May 26, 2024Updated last year
- "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.☆5,572Feb 8, 2025Updated last year
- A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.☆1,977Sep 5, 2021Updated 4 years ago
- Top disclosed reports from HackerOne☆5,358Updated this week
- This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.☆1,692Jun 20, 2022Updated 3 years ago
- A Python program to scrape secrets from GitHub through usage of a large repository of dorks.☆2,489Aug 3, 2024Updated last year
- A collection of tools to perform searches on GitHub.☆1,468Feb 9, 2023Updated 3 years ago
- A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..e…☆1,024Feb 22, 2026Updated last week
- Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature☆4,073Jul 31, 2024Updated last year
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3☆2,062Jan 2, 2024Updated 2 years ago
- ⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting☆4,532Feb 15, 2026Updated 2 weeks ago
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆1,039Aug 23, 2025Updated 6 months ago