securi3ytalent / bug-bounty-tipsView external linksLinks
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Online tips and explain the commands, for the better understanding of new hunters..
☆36Dec 8, 2023Updated 2 years ago
Alternatives and similar repositories for bug-bounty-tips
Users that are interested in bug-bounty-tips are comparing it to the libraries listed below
Sorting:
- Generate a cross join, also known as a Cartesian product, from the lines of the specified files. This process is useful for creating fuzz…☆21Jun 29, 2023Updated 2 years ago
- Javascript file change monitoring☆17Nov 11, 2025Updated 3 months ago
- A curated list of available Bug Bounty & Disclosure Programs and Write-ups.☆75Dec 3, 2023Updated 2 years ago
- Pointer is a Fast Simple Lightweight Tool for Endpoint Discovery.☆14Dec 30, 2023Updated 2 years ago
- At this repo you can find any tools, tricks or templates for general penetration testing assesment☆15Apr 27, 2024Updated last year
- Recon for Pentesting and BugBounty 🕵️☆13Jan 14, 2026Updated last month
- Ultimate List Of Bug Bounty Tools☆10Feb 25, 2023Updated 2 years ago
- ☆13Jun 26, 2025Updated 7 months ago
- Filter URLs that match your scope file for bugbounty.☆11May 23, 2023Updated 2 years ago
- Hey there! Welcome to my collection of bug bounty and security testing resources. Whether you're just starting out or already deep into y…☆11Dec 25, 2025Updated last month
- ☆13Oct 24, 2024Updated last year
- Good resources about web security that I have read.☆27Jul 23, 2023Updated 2 years ago
- Some Tutorials and Things to Help Bug Hunter☆31Mar 17, 2021Updated 4 years ago
- Bug Bounty Methodology-slides by Muhammad M. Awali. Pentesting and Researcher Talks.☆31Feb 17, 2023Updated 2 years ago
- List of custom Nuclei templates☆16Nov 4, 2023Updated 2 years ago
- Common Bugs from low to critical Level☆15May 9, 2021Updated 4 years ago
- This repository contains links to all the 100 days tweets that I posted during the #100DaysOfHacking challenge.☆17Apr 11, 2022Updated 3 years ago
- ☆111Apr 25, 2023Updated 2 years ago
- Looks for parameters in urls☆34Oct 14, 2024Updated last year
- A collaborative hub for Nuclei templates. Contribute, share, and explore powerful vulnerability detection tools!☆50Feb 1, 2025Updated last year
- ☆47Jan 14, 2024Updated 2 years ago
- CRLF Bug scanner for WebPentesters and Bugbounty Hunters☆44Jun 9, 2023Updated 2 years ago
- All in one web Recon app☆42Jun 11, 2024Updated last year
- 🌐 Get Some Useful Info From Domain/IP/ASN 🔥☆18Sep 29, 2024Updated last year
- This script will find some basic vulns. I made this script for my daily hunting. The best feature about this script is just run it in bac…☆20Feb 19, 2024Updated last year
- 🌎 Multi-threaded top level domain fuzzer. Discover already existed and available domains and subdomains!☆19Jan 12, 2026Updated last month
- BugSquasher Bug Bounty Tools List☆20Feb 2, 2023Updated 3 years ago
- Nuclei templates for drupal vulns... far from perfect☆18Jan 9, 2025Updated last year
- ☆19Nov 25, 2025Updated 2 months ago
- Notes taken from Android App Hacking - Black Belt Edition (UDEMY - Roman Stuehler)☆23May 19, 2024Updated last year
- My Notes & Resources Of Bug Bounty Checklists☆83Dec 28, 2024Updated last year
- URL Fuzzer☆21Nov 22, 2024Updated last year
- Cool resources and content for bug bounty hunting.☆19Oct 1, 2021Updated 4 years ago
- 🕵️♂️🔍 A tool with several scanning techniques that extracts live IP addresses from a list of IP addresses or CIDR notations.☆54May 14, 2023Updated 2 years ago
- Automate Nuclei scans and streamline bug hunting workflows☆21Feb 16, 2024Updated last year
- JS Finding can be used to extract JavaScript (JS) files from either a single domain URL or a list of domains. The tool supports various e…☆47Apr 29, 2024Updated last year
- TLDFinder is a Python package that identifies valid top-level domains (TLDs) for a list of domains with wildcard characters in the TLD.☆24Jul 2, 2023Updated 2 years ago
- WebApp intentionally made vulnerable to Race Condition for practicing Race Condition☆25Feb 23, 2022Updated 3 years ago
- ☆27Jul 5, 2023Updated 2 years ago