Bug Bounty writeups, Vulnerability Research, Tutorials, Tips&Tricks
☆211Aug 7, 2024Updated last year
Alternatives and similar repositories for research
Users that are interested in research are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.☆924Apr 22, 2026Updated 2 months ago
- ☆34Oct 1, 2019Updated 6 years ago
- BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source c…☆566Aug 25, 2022Updated 3 years ago
- Various tools for managing bug bounty recon and exploration.☆48Dec 8, 2022Updated 3 years ago
- Another plugin for CRLF vulnerability detection☆25Jan 25, 2017Updated 9 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- a .js scanner, built in php. designed to scrape urls and other info☆229Aug 22, 2017Updated 8 years ago
- this repository is a base so everyone can modify it according to there thoughts and process used☆10Jun 9, 2021Updated 5 years ago
- port+dir+param bruteforcing at the same time using ffuf☆17Jul 27, 2024Updated last year
- Tools of "The Bug Hunters Methodology V2 by @jhaddix"☆204Aug 11, 2017Updated 8 years ago
- An automation framework for running multiple open sourced subdomain bruteforcing tools (in parallel) using your own wordlists via Docker …☆261Aug 22, 2021Updated 4 years ago
- An entry level resource to learning bug bounty.☆28Apr 11, 2018Updated 8 years ago
- This repository contains all the material from the talk "Esoteric sub-domain enumeration techniques" given at Bugcrowd LevelUp 2017 virtu…☆634Feb 5, 2019Updated 7 years ago
- 根据关键字扫描github代码泄露☆11Oct 31, 2018Updated 7 years ago
- A collection of all the lists, scripts and techniques I use while doing web application penetration tests.☆168Feb 29, 2016Updated 10 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Some simple scripts that I use during bug bounty hunting in Android Apps☆29Jan 30, 2025Updated last year
- AutoTriageBot automatically verifies, deduplicates, and suggests payouts for incoming HackerOne reports.☆57Feb 12, 2022Updated 4 years ago
- Recon_profile☆38May 18, 2020Updated 6 years ago
- Multi Tool Subdomain Enumeration☆723Apr 11, 2021Updated 5 years ago
- Set up your own CTF with NIZKCTF☆14Oct 20, 2017Updated 8 years ago
- Fast subdomains enumeration tool for penetration testers☆117Feb 3, 2019Updated 7 years ago
- Highlight Burp proxy requests made by different browsers☆29Sep 21, 2017Updated 8 years ago
- Stealing CSRF tokens with CSS injection (without iFrames)☆322Feb 7, 2018Updated 8 years ago
- SSRF (Server Side Request Forgery) testing resources☆2,509Oct 12, 2024Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A simple python script which can check HTTP status of branch of URLs/Subdomains and grab URLs/Subdomain title☆12Oct 16, 2019Updated 6 years ago
- BountyDash is a tool to combine your rewards from all platforms, giving you insights about your progress and bug hunting patterns.☆164Apr 24, 2025Updated last year
- ☆334Jan 8, 2018Updated 8 years ago
- Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)☆462May 10, 2019Updated 7 years ago
- Automated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]☆304Oct 14, 2018Updated 7 years ago
- Setup script for Regon-ng☆940Nov 17, 2020Updated 5 years ago
- This tests a list of s3 buckets to see if they have dir listings enabled or if they are uploadable☆54Dec 10, 2025Updated 7 months ago
- ☆251Jun 6, 2018Updated 8 years ago
- A script to enumerate virtual hosts on a server.☆694Dec 28, 2017Updated 8 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆18Feb 4, 2016Updated 10 years ago
- Hunting Bugs for Fun and Profit☆277Jul 29, 2020Updated 5 years ago
- Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature☆4,227Jul 31, 2024Updated last year
- ☆632Feb 1, 2024Updated 2 years ago
- A collection of response templates for invalid bug bounty reports.☆90Feb 26, 2018Updated 8 years ago
- ☆842Nov 13, 2023Updated 2 years ago
- CTF writeups☆13Jul 2, 2017Updated 9 years ago