Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Onelinetips and explain the commands, for the better understanding of new hunters..
☆5,254Mar 13, 2026Updated last week
Alternatives and similar repositories for KingOfBugBountyTips
Users that are interested in KingOfBugBountyTips are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A collection of awesome one-liner scripts especially for bug bounty tips.☆3,088Jul 29, 2024Updated last year
- Collection of methodology and test case for various web vulnerabilities.☆7,057Jun 25, 2025Updated 9 months ago
- All about bug bounty (bypasses, payloads, and etc)☆6,672Sep 8, 2023Updated 2 years ago
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.☆6,113Aug 14, 2024Updated last year
- BBT - Bug Bounty Tools (examples💡)☆1,885Apr 5, 2024Updated last year
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference☆5,581Aug 6, 2023Updated 2 years ago
- This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for …☆3,675Updated this week
- A list of interesting payloads, tips and tricks for bug bounty hunters.☆6,399Sep 14, 2023Updated 2 years ago
- reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and findin…☆7,371Mar 20, 2026Updated last week
- 🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.☆4,884Updated this week
- The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, f…☆4,363Sep 30, 2024Updated last year
- GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep☆1,412Sep 13, 2024Updated last year
- A list of resources for those interested in getting started in bug bounties☆11,906Jul 23, 2024Updated last year
- Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing☆3,025Mar 7, 2026Updated 2 weeks ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.☆4,860Updated this week
- A collection of hacks and one-off scripts☆2,427Mar 13, 2025Updated last year
- Rockyou for web fuzzing☆3,094Mar 11, 2026Updated 2 weeks ago
- HTTP parameter discovery suite.☆6,154Feb 20, 2025Updated last year
- Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application☆5,007Dec 21, 2024Updated last year
- declutters url lists for crawling/pentesting☆1,538Feb 23, 2025Updated last year
- Automation for javascript recon in bug bounty.☆1,073Sep 9, 2023Updated 2 years ago
- reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via E…☆8,522Updated this week
- For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙☆1,823Jun 9, 2024Updated last year
- DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.☆1,694Jun 20, 2022Updated 3 years ago
- Hidden parameters discovery suite☆2,038Sep 8, 2024Updated last year
- The Swiss Army knife for automated Web Application Testing☆2,321May 8, 2024Updated last year
- A collection of tools to perform searches on GitHub.☆1,472Feb 9, 2023Updated 3 years ago
- A repository that includes all the important wordlists used while bug hunting.☆1,386Mar 11, 2023Updated 3 years ago
- "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.☆5,605Feb 8, 2025Updated last year
- A python script that finds endpoints in JavaScript files☆4,309Apr 13, 2024Updated last year
- List of Google Dorks for sites that have responsible disclosure program / bug bounty program☆1,911Dec 8, 2025Updated 3 months ago
- Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature☆4,080Jul 31, 2024Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..e…☆1,029Feb 22, 2026Updated last month
- Top disclosed reports from HackerOne☆5,426Feb 28, 2026Updated 3 weeks ago
- A Python program to scrape secrets from GitHub through usage of a large repository of dorks.☆2,496Aug 3, 2024Updated last year
- A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.☆1,985Sep 5, 2021Updated 4 years ago
- SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files☆2,407May 26, 2024Updated last year
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆1,040Aug 23, 2025Updated 7 months ago
- A curated list of various bug bounty tools☆5,853Feb 9, 2026Updated last month