zricethezav / h1domainsView external linksLinks
HackerOne "in scope" domains
☆500Updated this week
Alternatives and similar repositories for h1domains
Users that are interested in h1domains are comparing it to the libraries listed below
Sorting:
- This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for …☆3,639Updated this week
- GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep☆1,397Sep 13, 2024Updated last year
- This project crawls bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) hourly and dumps them into the bounty-targets-data…☆709Nov 18, 2025Updated 3 months ago
- Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!☆1,264Updated this week
- A collection of hacks and one-off scripts☆2,418Mar 13, 2025Updated 11 months ago
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.☆6,057Aug 14, 2024Updated last year
- Top disclosed reports from HackerOne☆5,297Jan 31, 2026Updated 2 weeks ago
- A python script that finds endpoints in JavaScript files☆4,280Apr 13, 2024Updated last year
- An hourly updated list of subdomains gathered from certificate transparency logs☆349Oct 13, 2021Updated 4 years ago
- Community curated list of public bug bounty and responsible disclosure programs.☆1,283Jan 5, 2026Updated last month
- HTTP parameter discovery suite.☆6,086Feb 20, 2025Updated 11 months ago
- SSRF (Server Side Request Forgery) testing resources☆2,484Oct 12, 2024Updated last year
- Extract SSL certificate data (Subject Name, Subject Alt Names, Organisation)☆42Nov 10, 2025Updated 3 months ago
- Pathbrute☆456Jun 3, 2020Updated 5 years ago
- "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.☆5,550Feb 8, 2025Updated last year
- BBT - Bug Bounty Tools (examples💡)☆1,881Apr 5, 2024Updated last year
- Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed b…☆1,028Feb 5, 2021Updated 5 years ago
- Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.☆4,821Jan 1, 2025Updated last year
- The Swiss Army knife for automated Web Application Testing☆2,324May 8, 2024Updated last year
- Asset inventory of over 800 public bug bounty programs.☆1,517Feb 14, 2025Updated last year
- The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, su…☆3,680Updated this week
- Find endpoints on GitHub.☆214Mar 28, 2023Updated 2 years ago
- ASN target organization IP range attack surface mapping for reconnaissance, fast and lightweight☆220Apr 10, 2022Updated 3 years ago
- a javascript change monitoring tool for bugbounties☆710Jul 31, 2024Updated last year
- A tool for adding new lines to files, skipping duplicates☆1,605Jan 12, 2024Updated 2 years ago
- MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering…☆1,588Feb 9, 2026Updated last week
- ☆1,405Jan 22, 2026Updated 3 weeks ago
- Automatic SSRF fuzzer and exploitation tool☆3,485Sep 4, 2025Updated 5 months ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆642Jul 7, 2025Updated 7 months ago
- A Tool for Domain Flyovers☆5,897May 22, 2022Updated 3 years ago
- Secret and/or credential patterns used for gf.☆243Feb 10, 2023Updated 3 years ago
- Fetches javascript file from a list of URLS or subdomains.☆834Jul 22, 2025Updated 6 months ago
- Automation for javascript recon in bug bounty.☆1,067Sep 9, 2023Updated 2 years ago
- HTTP file upload scanner for Burp Proxy☆491Dec 25, 2023Updated 2 years ago
- Subdomain Takeover tool written in Go☆2,026Aug 13, 2023Updated 2 years ago
- Gospider - Fast web spider written in Go☆2,869Apr 21, 2024Updated last year
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆303Feb 12, 2023Updated 3 years ago
- Rockyou for web fuzzing☆3,017Updated this week
- Maintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.☆727Jan 16, 2024Updated 2 years ago