bugbounty-tool

Open-source projects categorized as bugbounty-tool

Top 21 bugbounty-tool Open-Source Projects

  • dalfox

    πŸŒ™πŸ¦Š Dalfox is a powerful open-source XSS scanner and utility focused on automation.

  • malicious-pdf

    πŸ’€ Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

  • Project mention: Securing PDF Generators Against SSRF Vulnerabilities | /r/netsec | 2023-05-30

    Wrote a tool two years ago that does some of the PDF-tests. But more could be added: https://github.com/jonaslejon/malicious-pdf

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • inql

    InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

  • Galaxy-Bugbounty-Checklist

    Tips and Tutorials for Bug Bounty and also Penetration Tests.

  • go-dork

    The fastest dork scanner written in Go.

  • Payloads

    Payload Arsenal for Pentration Tester and Bug Bounty Hunters (by sh377c0d3)

  • Garud

    An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  • ppfuzz

    A fast tool to scan client-side prototype pollution vulnerability written in Rust. πŸ¦€

  • ppmap

    A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

  • csprecon

    Discover new target domains using Content Security Policy

  • GRecon

    Another version of katana, more automated but less stable. the purpose of this small tool is to run a Google based passive recon against your scope.

  • Reconky-Automated_Bash_Script

    Reconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which help them to look forward.

  • web-hacking-toolkit

    A web hacking toolkit (docker image).

  • webstor

    WebStor efficiently enumerates all websites across your organization’s networks and those in your DNS records - including cloud-hosted servers via zone transfer data - stores their responses, and lets you query for known web technologies, including those with zero-day vulnerabilities.

  • PassDetective

    PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords, API keys, and secrets. Using regular expressions, it helps prevent accidental exposure of sensitive information in your command history.

  • Project mention: PassDetective has released on Kali Linux | news.ycombinator.com | 2023-12-01
  • Discord-Recon

    Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server

  • s1c0n

    simple recon tool to help you for searching vulnerability on web server

  • CloudSniffer

    CloudSniffer is a powerful tool designed to aid in the discovery of the real IP address of a website protected by Cloudflare. It leverages brute force techniques by testing a list of IP addresses and analyzing the status codes returned by the server to uncover the actual IP address of the target website.

  • Project mention: Privacy | /r/selfhosted | 2023-07-01
  • OrgASM

    A tool for Oragnized ASM (Attack Surface Mapper). Subdomains enumeration, IPs scans, Vulnerability assesment...

  • Project mention: New Attack Surface Discovery tool : OrgASM | /r/cybersecurity | 2023-05-31
  • Recon-Plus

    A Unified Reconnaissance Tool for Pentesting

  • BurpPro-FastCrawler

    The simplest way to integrate your subdomain enum outputs with Burp Pro (Fast Crawler)

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

bugbounty-tool related posts

  • PassDetective has released on Kali Linux

    1 project | news.ycombinator.com | 1 Dec 2023
  • Introducing PassDetective: Your Guardian Against Accidental Data Exposure in Command History! πŸ›‘οΈπŸ•΅οΈβ€β™‚οΈ

    1 project | /r/Hacking_Tutorials | 26 Jul 2023
  • Introducing PassDetective: Your Guardian Against Accidental Data Exposure in Command History! πŸ›‘οΈπŸ•΅οΈβ€β™‚οΈ

    1 project | /r/blueteamsec | 26 Jul 2023
  • Introducing PassDetective: Your Guardian Against Accidental Data Exposure in Command History! πŸ›‘οΈπŸ•΅οΈβ€β™‚οΈ

    1 project | /r/golang | 24 Jul 2023
  • Introducing PassDetective: Your Guardian Against Accidental Data Exposure in Command History! πŸ›‘οΈπŸ•΅οΈβ€β™‚οΈ

    1 project | /r/blackhat | 24 Jul 2023
  • Introducing PassDetective: Your Guardian Against Accidental Data Exposure in Command History! πŸ›‘οΈπŸ•΅οΈβ€β™‚οΈ

    1 project | /r/Information_Security | 24 Jul 2023
  • Introducing PassDetective: Your Guardian Against Accidental Data Exposure in Command History! πŸ›‘οΈπŸ•΅οΈβ€β™‚οΈ

    1 project | /r/redteamsec | 24 Jul 2023
  • A note from our sponsor - SaaSHub
    www.saashub.com | 17 May 2024
    SaaSHub helps you find the best software and product alternatives Learn more β†’

Index

What are some of the best open-source bugbounty-tool projects? This list will help you:

Project Stars
1 dalfox 3,324
2 malicious-pdf 2,693
3 inql 1,470
4 Galaxy-Bugbounty-Checklist 1,324
5 go-dork 998
6 Payloads 840
7 Garud 750
8 ppfuzz 542
9 ppmap 446
10 csprecon 320
11 GRecon 210
12 Reconky-Automated_Bash_Script 193
13 web-hacking-toolkit 155
14 webstor 150
15 PassDetective 108
16 Discord-Recon 69
17 s1c0n 59
18 CloudSniffer 53
19 OrgASM 26
20 Recon-Plus 9
21 BurpPro-FastCrawler 7

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com