hakluke / bug-bounty-standards
A list of edge cases that occur in bug bounty programs, conversations on how they should be handled. The goal is to standardise the way that specific situations are handled in bug bounties.
☆229Updated 2 years ago
Alternatives and similar repositories for bug-bounty-standards:
Users that are interested in bug-bounty-standards are comparing it to the libraries listed below
- Burp extension to create target specific and tailored wordlist from burp history.☆233Updated 3 years ago
- ☆161Updated 2 months ago
- De-clutter a list of URLs☆312Updated last month
- Repository to house markdown templates for researchers☆194Updated this week
- EvenBetter is a frontend Caido plugin that makes the Caido experience even better 😎☆140Updated 2 weeks ago
- List of reporting templates I have used since I started doing BBH.☆245Updated 4 months ago
- ☆152Updated last year
- Unofficial documentation for the great tool Param Miner☆176Updated 2 years ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆300Updated 2 months ago
- Useful "Match and Replace" burpsuite rules☆340Updated last year
- Whitebox source code review cheatsheet (Based on AWAE syllabus)☆123Updated 2 years ago
- ☆155Updated 6 months ago
- ☆99Updated last year
- ☆140Updated 2 years ago
- Top disclosed reports from HackerOne☆147Updated 3 years ago
- CT Log Scanner☆305Updated 3 months ago
- ☆147Updated last year
- ☆237Updated 3 years ago
- Recon MindMap (RMM)☆146Updated 7 months ago
- ☆97Updated 2 years ago
- This is a python wrapper around the amazing KNOXSS API by Brute Logic☆236Updated this week
- Prototype pollution scanner using headless chrome☆198Updated 2 years ago
- A Firefox Web Extension to improve the discovery of DOM XSS.☆266Updated 2 months ago
- Pass in a list of URLs with query strings, get back a unique list of URLs and query string combinations☆348Updated 4 years ago
- ☆122Updated 3 years ago
- Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.☆412Updated 3 months ago
- GQLSpection - parses GraphQL introspection schema and generates possible queries☆74Updated 6 months ago
- Automated tool for domains & subdomains gathering☆182Updated last year