Documenting my security research journey: This repository contains detailed vulnerability write-ups, proof-of-concept (PoC) exploits, and the custom automation tools I use for reconnaissance and system assessment.
☆201Oct 1, 2026Updated this week
Alternatives and similar repositories for bug-bounty
Users that are interested in bug-bounty are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An obsessive, expert-tier knowledge base + AI skill system for professional bug bounty hunting, security research, and penetration testin…☆54Apr 25, 2026Updated 5 months ago
- Hands-on cybersecurity projects built for learning, experimentation, and practical security research — featuring offensive and defensive …☆22Aug 13, 2026Updated last month
- Explore free, self-hostable network services & web apps: email, file sharing, CMS, and more. Includes setup guides and Docker support for…☆16Apr 16, 2026Updated 5 months ago
- A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug…☆19May 20, 2026Updated 4 months ago
- GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's …☆38Apr 12, 2026Updated 5 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Personal Web Application Pentesting Methodology built during my cybersecurity learning journey. Covers reconnaissance, scanning, fuzzing,…☆58Jul 24, 2026Updated 2 months ago
- Protecting your data has never been more important. My cyber security blog is here to help you stay ahead of the game. I cover a wide ran…☆19Updated this week
- Full-stack server fingerprinting tool for bug bounty hunters — auto-detects server, CDN, WAF, SSL, ports & more☆19Mar 8, 2026Updated 6 months ago
- HaXder is an advanced, asynchronous reconnaissance framework for security researchers. Discover subdomains, map attack surfaces, fingerpr…☆50Jul 1, 2026Updated 3 months ago
- Auth Mutator is a Burp Suite extension that helps you experiment with mutated authentication requests while keeping the original traffic …☆16Sep 1, 2026Updated last month
- ☆79May 5, 2025Updated last year
- ☆11Nov 26, 2016Updated 9 years ago
- Proof of concept exploit about OpenSSL signature_algorithms_cert DoS flaw (CVE-2020-1967)☆20Jun 16, 2024Updated 2 years ago
- powerfull pentesting tool to checking email by smtp command☆10Feb 29, 2024Updated 2 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- 必应每日壁纸数据采集脚本、必应壁纸历史数据API和必应壁纸在线浏览。☆10Dec 31, 2020Updated 5 years ago
- ALL IN ONE Hacking Tool For Hackers☆17Apr 1, 2022Updated 4 years ago
- At this repo you can find any tools, tricks or templates for general penetration testing assesment☆16Apr 27, 2024Updated 2 years ago
- A structured and beginner-friendly knowledge base for learning Certified Ethical Hacker (CEH v13) concepts. This repository contains cle…☆36Mar 11, 2026Updated 6 months ago
- PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE☆16Jun 11, 2026Updated 3 months ago
- Gampung tools for find nuclei template from github☆12Sep 6, 2023Updated 3 years ago
- This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter☆35Feb 10, 2024Updated 2 years ago
- 🗄 CLI archival tool for the Wayback Machine☆11Mar 5, 2023Updated 3 years ago
- Certified ethical hacker V13 AI Study notes☆27Jan 27, 2026Updated 8 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- CVE-2026-63030, CVE-2026-60137, wp2shell scanner☆66Jul 18, 2026Updated 2 months ago
- Interactive XSS Labs to get into Client-Side Hacking☆95Feb 25, 2026Updated 7 months ago
- Stealth hybrid URL mapper☆31May 1, 2026Updated 5 months ago
- PoC for iOS, macOS, iPadOS (DoS)☆16Jan 14, 2022Updated 4 years ago
- Playback webpages from Wayback Machine☆13Aug 22, 2026Updated last month
- Exploit code for CVE-2023-42914 / pwn2own Vancouver 2023☆16Nov 22, 2024Updated last year
- Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.☆18Feb 1, 2026Updated 8 months ago
- aplikasi surat menyurat☆11Jan 3, 2023Updated 3 years ago
- ☆11Mar 16, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- One-Click to Completely Take Over A macOS Device☆18Aug 25, 2022Updated 4 years ago
- A Python tool to resolve domains to IPs, fetch related CVEs, and display open ports☆17Nov 21, 2025Updated 10 months ago
- CLI script to use GadgetProbe as a library to generate serialized payloads of DNS callbacks to free DNSbin to probe what Java classpaths …☆14Jun 8, 2021Updated 5 years ago
- Example of CVE-2022-46689 aka MacDirtyCow.☆14Mar 1, 2023Updated 3 years ago
- A collection of Apple-related CTF writeups☆16Jan 17, 2022Updated 4 years ago
- A guide to using Kali Linux tools for web penetration testing, ethical hacking, forensics, and bug bounty. Covers setup, key tools, metho…☆281Aug 14, 2026Updated last month
- Turn your hand into a fully functional in-air mouse using Python, OpenCV, and MediaPipe.☆16Jul 27, 2026Updated 2 months ago