Go Bugbounty

Open-source Go projects categorized as Bugbounty

Top 23 Go Bugbounty Projects

  1. subfinder

    Fast passive subdomain enumeration tool.

    Project mention: When internal hostnames are leaked to the clown | news.ycombinator.com | 2026-02-04

    Much better. But you still leave traces from dns queries.

    Subfinder has a lot of sources to find subdomains, not only certs: https://github.com/projectdiscovery/subfinder

  2. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  3. hetty

    An HTTP toolkit for security research.

  4. httpx

    httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library. (by projectdiscovery)

    Project mention: Simple Hacking Technique for Beginners (2025 Edition) | dev.to | 2025-12-08

    - [nuclei](https://github.com/projectdiscovery/nuclei): A fast and customizable vulnerability scanner based on simple YAML based DSL. - [nuclei-templates](https://github.com/projectdiscovery/nuclei-templates): Community curated list of templates for the nuclei engine to find security vulnerabilities. - [subfinder](https://github.com/projectdiscovery/subfinder): A fast passive subdomain enumeration tool leveraging dozens of APIs. - [httpx](https://github.com/projectdiscovery/httpx): A fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library. - [cvemap](https://github.com/projectdiscovery/cvemap): A CLI to Navigate the CVE jungle with ease. - [katana](https://github.com/projectdiscovery/katana): A next-generation crawling and spidering framework. - [naabu](https://github.com/projectdiscovery/naabu): A fast port scanner written in go with a focus on reliability and simplicity.

  5. osmedeus

    A Modern Orchestration Engine for Security

  6. scan4all

    Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

  7. hakrawler

    Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

  8. interactsh

    An OOB interaction gathering server and client library

  9. cariddi

    Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

  10. OneListForAll

    Rockyou for web fuzzing

  11. S3Scanner

    Scan for misconfigured S3 buckets across S3-compatible APIs!

  12. uncover

    Quickly discover exposed hosts on the internet using multiple search engines.

  13. jaeles

    The Swiss Army knife for automated Web Application Testing

  14. puredns

    Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.

  15. nomore403

    🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.

  16. gotestwaf

    An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

  17. urlhunter

    a recon tool that allows searching on URLs that are exposed via shortener services

  18. metabigor

    OSINT tools and more but without API key

  19. git-hound

    Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

  20. go-dork

    The fastest dork scanner written in Go.

  21. scilla

    Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

  22. shortscan

    An IIS short filename enumeration tool

  23. CloudBrute

    Awesome cloud enumerator

  24. cent

    Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place (by xm1k3)

NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Go Bugbounty discussion

Log in or Post with

Go Bugbounty related posts

  • Show HN: I made a tool to strip GPS and EXIF metadata from photos client-side

    1 project | news.ycombinator.com | 3 Jan 2026
  • Simple Hacking Technique for Beginners (2025 Edition)

    13 projects | dev.to | 8 Dec 2025
  • Show HN: ProjectDiscoverys Subfinder > Android App in <30M – Claude Code

    2 projects | news.ycombinator.com | 15 Oct 2025
  • Crawl URLs and scan for endpoints, secrets, file extensions

    1 project | news.ycombinator.com | 9 Jun 2025
  • Ask HN: Is there a service that offers Common Crawl as an API?

    1 project | news.ycombinator.com | 9 May 2025
  • Recon v2: Um curto update sobre como estou mudando meu processo de recon

    1 project | dev.to | 9 Feb 2025
  • Subfinder: Fast passive subdomain enumeration tool

    1 project | news.ycombinator.com | 16 Jan 2025
  • A note from our sponsor - SaaSHub
    www.saashub.com | 13 Jun 2026
    SaaSHub helps you find the best software and product alternatives Learn more →

Index

What are some of the best open-source Bugbounty projects in Go? This list will help you:

# Project Stars
1 subfinder 13,812
2 hetty 10,136
3 httpx 10,032
4 osmedeus 6,412
5 scan4all 5,987
6 hakrawler 5,007
7 interactsh 4,370
8 cariddi 3,411
9 OneListForAll 3,166
10 S3Scanner 3,092
11 uncover 2,969
12 jaeles 2,336
13 puredns 2,189
14 nomore403 1,789
15 gotestwaf 1,789
16 urlhunter 1,677
17 metabigor 1,542
18 git-hound 1,427
19 go-dork 1,280
20 scilla 1,236
21 shortscan 1,162
22 CloudBrute 1,127
23 cent 1,044

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com