Documenting my security research journey: This repository contains detailed vulnerability write-ups, proof-of-concept (PoC) exploits, and the custom automation tools I use for reconnaissance and system assessment.
☆161Sep 12, 2026Updated this week
Alternatives and similar repositories for bug-bounty
Users that are interested in bug-bounty are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An obsessive, expert-tier knowledge base + AI skill system for professional bug bounty hunting, security research, and penetration testin…☆46Apr 25, 2026Updated 4 months ago
- A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug…☆18May 20, 2026Updated 3 months ago
- GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's …☆38Apr 12, 2026Updated 5 months ago
- Personal Web Application Pentesting Methodology built during my cybersecurity learning journey. Covers reconnaissance, scanning, fuzzing,…☆58Jul 24, 2026Updated last month
- Auth Mutator is a Burp Suite extension that helps you experiment with mutated authentication requests while keeping the original traffic …☆16Sep 1, 2026Updated last week
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Welcome to the Bug Bounty Methodology 2026 Edition!☆88Mar 28, 2026Updated 5 months ago
- Tutorial Dasar Codeigniter☆13Oct 3, 2019Updated 6 years ago
- Full-stack server fingerprinting tool for bug bounty hunters — auto-detects server, CDN, WAF, SSL, ports & more☆19Mar 8, 2026Updated 6 months ago
- Stealth hybrid URL mapper☆31May 1, 2026Updated 4 months ago
- HaXder is an advanced, asynchronous reconnaissance framework for security researchers. Discover subdomains, map attack surfaces, fingerpr…☆48Jul 1, 2026Updated 2 months ago
- ☆79May 5, 2025Updated last year
- PenTest and BugBounty 🕵️☆16Aug 18, 2026Updated 3 weeks ago
- ☆10Jan 22, 2016Updated 10 years ago
- ☆16Oct 14, 2022Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods☆26Jul 15, 2026Updated last month
- ex-redirect — An automated open redirect scanner using Wayback Machine archives. Supports subdomain grouping, live URL filtering, and Wor…☆15May 9, 2025Updated last year
- ☆96May 11, 2026Updated 4 months ago
- Fast Go-based XSS assessment toolkit☆20Mar 18, 2026Updated 5 months ago
- Some CTFs and challenges writeups from differents CTF Platforms☆17Oct 31, 2025Updated 10 months ago
- Lightweight Windows disassembler, PE inspection and patch-assistance tool for native EXE/DLL files.☆17Jun 29, 2026Updated 2 months ago
- Proof of concept exploit about OpenSSL signature_algorithms_cert DoS flaw (CVE-2020-1967)☆20Jun 16, 2024Updated 2 years ago
- Interactive XSS Labs to get into Client-Side Hacking☆96Feb 25, 2026Updated 6 months ago
- powerfull pentesting tool to checking email by smtp command☆10Feb 29, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- List of Public Bug Bounty and Responsible Disclosure Programs☆27Dec 11, 2025Updated 9 months ago
- Burp Suite extension to detect Web Cache Deception vulnerabilities, now compatible with the Community Edition. Automates advanced cache …☆19Jun 11, 2026Updated 3 months ago
- Pentest and manual code review templates -- web/API, cloud (AWS/GCP/Azure), mobile (iOS/Android), thick client, hardware/IoT, plus 11 lan…☆32Apr 12, 2026Updated 5 months ago
- 必应每日壁纸数据采集脚本、必应壁纸历史数据API和必应壁纸在线浏览。☆10Dec 31, 2020Updated 5 years ago
- PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE☆16Jun 11, 2026Updated 3 months ago
- CVE-2026-63030, CVE-2026-60137, wp2shell scanner☆63Jul 18, 2026Updated last month
- A diagnostic methodology for bypassing LLM defense layers — from input filters to persistent memory exploitation.☆43May 8, 2026Updated 4 months ago
- This is the report that goes with my mock full-scope red team engagement against Game of Active Directory.☆20Oct 26, 2025Updated 10 months ago
- 🗄 CLI archival tool for the Wayback Machine☆11Mar 5, 2023Updated 3 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 7 months ago
- Next-gen XSS scanner with runtime verification, context-aware exploitation, and 8 advanced detection modules. Zero false positives. Built…☆23Jan 12, 2026Updated 8 months ago
- Bug bounty methodology, checklists, and hunting notes.☆35Jul 10, 2026Updated 2 months ago
- ☆13Mar 18, 2023Updated 3 years ago
- F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB☆13May 11, 2023Updated 3 years ago
- ☆14Jul 19, 2026Updated last month
- PoC for iOS, macOS, iPadOS (DoS)☆16Jan 14, 2022Updated 4 years ago