Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
bugbounty-lab101 — Ein kompletter Bug-Bounty-Arbeitsbereich für HackerOne-Forscher. Enthält Scope-Durchsetzung, eine automatisierte Recon-/Schwachstellen-Pipeline (400+ Tools), Berichtsvorlagen, CVE-/CWE-Beobachtungslisten und ein lokales VM-Übungslabor. Entwickelt für diszipliniertes, ethisches Jagen. | Kitploit
Tools/GitHubGitHub/devcop95/bugbounty-lab101
AufklärungSchwachstellenscannerWeb-SchwachstellenscannerScripting & AutomatisierungWebanwendungs-ExploitationAPI-SicherheitstestsInformationsbeschaffungPenetrationstests

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Subdomain-Enumeration
Lernen & Bildung
Labs & Praxis
GitHubdevcop95/bugbounty-lab101

bugbounty-lab101

Repository anzeigen
411723vor 1 MonatVon Kitploit geprüft

Über

Ein kompletter Bug-Bounty-Arbeitsbereich für HackerOne-Forscher. Enthält Scope-Durchsetzung, eine automatisierte Recon-/Schwachstellen-Pipeline (400+ Tools), Berichtsvorlagen, CVE-/CWE-Beobachtungslisten und ein lokales VM-Übungslabor. Entwickelt für diszipliniertes, ethisches Jagen.

Teilen
root@kitploit:~
          ██████╗ ███████╗██╗   ██╗ ██╗ ██████╗  ██╗██╗  ██╗
          ██╔══██╗██╔════╝██║   ██║███║██╔═████╗███║╚██╗██╔╝
          ██║  ██║█████╗  ██║   ██║╚██║██║██╔██║╚██║ ╚███╔╝
          ██║  ██║██╔══╝  ╚██╗ ██╔╝ ██║████╔╝██║ ██║ ██╔██╗
          ██████╔╝███████╗ ╚████╔╝  ██║╚██████╔╝ ██║██╔╝ ██╗
          ╚═════╝ ╚══════╝  ╚═══╝   ╚═╝ ╚═════╝  ╚═╝╚═╝  ╚═╝

BUG BOUNTY LAB

Bug-Bounty-Arbeitsumgebung für HackerOne-Researcher

Stars Forks License HackerOne

Kali Linux
Tools
Scope Safe

Inhaltsverzeichnis

  • Was ist das?
  • Schnellstart
  • T3MP3ST — KI-gestützter War Room
  • Hauptbefehle
  • Tool-Matrix nach Phase
  • Tools nach Kategorie
  • Report-Beispiel
  • Workflow
  • Üben, ohne echte Programme anzufassen
  • Projektstruktur
  • Wichtige Regeln
  • Fehlerbehebung
  • Lernressourcen
  • Changelog

Was ist das?

Eine Arbeitsumgebung, die um den echten Bug-Bounty-Workflow auf HackerOne herum aufgebaut ist: Programm auswählen, Scope dokumentieren, innerhalb der Grenzen scannen, Findings verketten und in einem Format reporten, das Triager schnell akzeptieren. Das generische Pentesting-Arsenal mit 400+ Tools und das lokale VM-Lab stehen unterstützend zur Verfügung — nicht als Einstiegspunkt.

root@kitploit:~
┌─────────────────────────────────────────────────────────────────────┐
│                                                                     │
│  SCOPE                RECON/VULN              REPORT                │
│  ═════                ══════════              ══════                │
│                                                                     │
│  ┌───────────┐      ┌───────────────────┐    ┌───────────────┐      │
│  │programs/  │────▶  bugbounty-hunter   ───▶  report.md     │      │
│  │*.md       │      │      .sh          │    │ (H1 template) │      │
│  └───────────┘      └────────┬──────────┘    └───────┬───────┘      │
│  scope check                 │                       │              │
│  (blocks if not              ▼                       ▼              │
│   documented)       ┌─────────────┐         ┌──────────────┐        │
│                     │auto-scanner │         │  Hacktivity  │        │
│                     │ (arsenal)   │         │  dedup check │        │
│                     └─────────────┘         └──────────────┘        │
│                                                                     │
└─────────────────────────────────────────────────────────────────────┘

Schnellstart

1. Berechtigungen

root@kitploit:~
cd bugbounty-lab101
chmod +x bugbounty/*.sh auto-scanner/*.sh
# If the repository was cloned without submodules:
git submodule update --init --recursive

2. Programm-Scope dokumentieren

root@kitploit:~
cd bugbounty
./bugbounty-hunter.sh new program-name
# Edit ../programs/program-name.md with the EXACT scope from the H1 policy

3. Scope verifizieren und scannen

root@kitploit:~
./bugbounty-hunter.sh scope target.com     # must say "Scope OK" before proceeding
./bugbounty-hunter.sh full target.com       # recon -> vuln -> brute -> secrets -> api -> report

4. Report

root@kitploit:~
./bugbounty-hunter.sh report target.com
# Complete bugbounty/reports/target.com/report-YYYYMMDD.md with the H1 template

Vor dem Einreichen docs/hackerone-workflow.md lesen (Hacktivity-Deduplizierung, Report-Qualität, Schritte nach der Einreichung).


T3MP3ST — KI-gestützter War Room

Dieses Lab integriert T3MP3ST als seine Offensive-Security-Engine — ein Multi-Agent-Framework, das deinen KI-Coding-Agenten in einen Zero-Day-Jäger verwandelt.

Einrichtung

root@kitploit:~
# 1. Clone T3MP3ST into the lab (it's .gitignored, separate repo)
git clone https://github.com/DevCop95/T3MP3ST t3mp3st
cd t3mp3st && npm install && cd ..

# 2. Configure API keys
cp t3mp3st/.env.example t3mp3st/.env
# Edit t3mp3st/.env with your LLM provider key(s)

# 3. Start the server
./start-server.sh
# War Room → http://127.0.0.1:3333/ui/

Was T3MP3ST bietet

FeatureBeschreibung
War Room UIWeb-Oberfläche für Missionsplanung und -ausführung
Recon Enginenmap, DNS, HTTP-Fingerprinting — 90,1 % pass@1 auf XBEN
Exploit Loop8-Operator-Kill-Chain (Recon → Scanner → Exploiter → ...)
Payload DB200+ Payloads (SQLi, XSS, SSTI, LFI, SSRF, CMDi, XXE)
MCP Servernode t3mp3st/dist/mcp-server.js für Agent-Integration
Evidence VaultPersistente Findings, Evidenzen und Retest-Tracking

Keyless-Modus

T3MP3ST funktioniert ohne API-Keys, indem du deinen lokalen KI-Agenten (Claude Code, Codex, Hermes) verbindest. Öffne in der War-Room-UI die Settings und verbinde deinen Agenten — beschreibe dann Ziele in einfachem Englisch.


Hauptbefehle

BefehlBeschreibungBeispiel
bugbounty-hunter.sh new <prog>Scope-Tracker für ein Programm erstellen./bugbounty-hunter.sh new acme-corp
bugbounty-hunter.sh scope <target>Verifizieren, dass das Ziel im Scope liegt./bugbounty-hunter.sh scope target.com
bugbounty-hunter.sh full <target>Vollständige Pipeline (Recon bis Report)./bugbounty-hunter.sh full target.com
bugbounty-hunter.sh recon <target>Nur Recon, inklusive passiver Shodan-CTL-Anreicherung./bugbounty-hunter.sh recon target.com
bugbounty-hunter.sh report <target>Report mit H1-Template generieren./bugbounty-hunter.sh report target.com
pentest.sh <url>Generisches Arsenal (400+ Tools)pentest.sh https://target.com
pentest.sh matrixVollständige Tool-Matrixpentest.sh matrix
pentest.sh search <function>Nach einem Tool suchenpentest.sh search sql_injection
pentest.sh express <url>Express-Scanpentest.sh express https://target.com
pentest.sh installFehlende Tools installierenpentest.sh install
./start-server.shT3MP3ST War Room starten (KI-gestützt)./start-server.sh
npm run serverT3MP3ST aus dem t3mp3st/-Verzeichnis startencd t3mp3st && npm run server

Alle aktiven Scan-Befehle in bugbounty-hunter.sh verifizieren den Scope gegen programs/*.md, bevor das Ziel angefasst wird. Die passive Shodan-CTL-Integration ist optional und verwendet das gepinnte vendor/shodan_reconsx-Submodul, wenn recons101x nicht installiert ist. Seine Hostnamen werden vor jedem HTTP-Probing scope-gefiltert.


Tool-Matrix nach Phase

root@kitploit:~
╔═════════════════════════════════════════════════════════════════════════╗
║                                                                         ║
║  PHASE 1          PHASE 2          PHASE 3          PHASE 4             ║
║  RECON            SCANNING         ENUMERATION      EXPLOITATION        ║
║                                                                         ║
║  ┌───────────┐   ┌───────────┐   ┌───────────┐   ┌───────────┐          ║
║  │   nmap    │─▶   nikto     ──▶  enum4l     ──▶  sqlmap              
║  │   amass   │   │ gobuster  │   │  smbclnt  │   │metasploit │          ║
║  │   dig     │   │  whatweb  │   │  ldapsrc  │   │  xsser    │          ║
║  │   whois   │   │   wfuzz   │   │  rpcclnt  │   │  wpscan   │          ║
║  └───────────┘   └───────────┘   └───────────┘   └───────────┘          ║
║        │              │               │               │                 ║
║        ▼              ▼               ▼               ▼                 ║
║  ┌───────────┐   ┌───────────┐   ┌───────────┐   ┌───────────┐          ║
║  │  theHarv  │   │   dirb    │   │ snmpwalk  │   │ msfvenom  │          ║
║  │  recon-ng │   │   ffuf    │   │  nbtscan  │   │ searchsp  │          ║
║  └───────────┘   └───────────┘   └───────────┘   └───────────┘          ║
║                                                                         ║
╠═════════════════════════════════════════════════════════════════════════╣
║                                                                         ║
║  PHASE 5          PHASE 6          PHASE 7          PHASE 8             ║
║  BUSINESS LOGIC   API TESTING      CHAIN ATTACKS    REPORT              ║
║                                                                         ║
║  ┌───────────┐   ┌───────────┐   ┌───────────┐   ┌───────────┐          ║
║  │auth flow  │   │  swagger  │   │CORS+CSRF  │   │    H1     │          ║
║  │race cond  │   │  graphql  │   │SSRF+RCE   │   │  REPORT   │          ║
║  │mass assn  │   │  nuclei   │   │IDOR+priv  │   │   .md     │          ║
║  └───────────┘   └───────────┘   └───────────┘   └───────────┘          ║
║                                                                         ║
╚═════════════════════════════════════════════════════════════════════════╝

Tools nach Kategorie (auto-scanner/ — unterstützendes Arsenal)

Reconnaissance (50+ Tools)

root@kitploit:~
┌────────────────────────────────────────────────────────────────┐
│  NETWORK SCANNING:                                             │
│  nmap        masscan      zmap         unicornscan             │
│  netdiscover                                                   │
│                                                                │
│  DNS ENUMERATION:                                              │
│  dnsrecon    dig          host         dnsenum                 │
│  dnsmap      sublist3r    subfinder    subbrute                │
│  dnsgen      gotator      fierce       dnspoodle               │
│                                                                │
│  HTTP RECON:                                                   │
│  httpx       httprobe     gau          waybackurls             │
│  katana      gospider     hakrawler    linkfinder              │
│  jsfinder    secretfinder paramspider  arjun                   │
│                                                                │
│  CLOUD RECON:                                                  │
│  s3scanner   cloud_enum   lazys3       bucket_finder           │
│                                                                │
│  SUBDOMAIN TAKEOVER:                                           │
│  subjack     subover      nuclei       canari                  │
└────────────────────────────────────────────────────────────────┘

Web (20+ Tools)

root@kitploit:~
┌─────────────────────────────────────────────────────────────────┐
│  SCANNERS:        nikto  whatweb  wapiti  arachni  skipfish     │
│  DIRECTORY BRUTE: gobuster  dirb  feroxbuster  dirsearch        │
│  FUZZING:         wfuzz  ffuf  arjun  x8  paramspider           │
│  VULNERABILITIES: sqlmap  xsser  dalfox  commix  xsstrike       │
│  CMS:             wpscan  joomscan  droopescan  cmseek  cariddi │
└─────────────────────────────────────────────────────────────────┘

Report-Beispiel (HackerOne-Format)

root@kitploit:~
# Bug Bounty Report

## Platform
HackerOne

## Program
[program name]

## Researcher
[your-handle]

## Target
prime.example.com

## Weakness (H1 taxonomy)
CWE-538: Insertion of Sensitive Information into Externally-Accessible File

## Executive Summary
S3 bucket with listing enabled exposes N files without authentication,
including internal HR documents.

## Steps to Reproduce
1. curl -k https://prime.example.com/file-service/static/
2. ...

## Impact
[Concrete business impact, not generic]

Vollständiges Template unter bugbounty/templates/report-template.md.


Workflow

root@kitploit:~
                      ┌─────────────────────┐
                      │  Choose H1 Program  │
                      └──────────┬──────────┘
                                 ▼
                      ┌─────────────────────┐
                      │ bugbounty-hunter.sh │
                      │   new <program>     │
                      └──────────┬──────────┘
                                 ▼
                      ┌─────────────────────┐
                      │  Document scope in  │
                      │   programs/*.md     │
                      └──────────┬──────────┘
                                 ▼
                ┌────────────────────────────────┐
                │ bugbounty-hunter.sh full <t>   │
                └────────────────┬───────────────┘
                                 │
              ┌──────────────────┼──────────────────┐
              ▼                  ▼                  ▼
       ┌──────────────┐   ┌──────────────┐   ┌──────────────┐
       │ RECON/VULN   │   │ MANUAL VERIF │   │ CHAIN ATTACK │
       │  (scripts)   │   │  (manual)    │   │  (manual)    │
       └──────┬───────┘   └──────┬───────┘   └──────┬───────┘
              └──────────────────┼──────────────────┘
                                 ▼
                      ┌─────────────────────┐
                      │  Dedup in Hacktivity│
                      └──────────┬──────────┘
                                 ▼
                      ┌─────────────────────┐
                      │  Submit H1 Report   │
                      └─────────────────────┘

Vollständige Methodik unter docs/hackerone-workflow.md.


Üben, ohne echte Programme anzufassen

legacy-vm-practice/ gehört dir: private IPs, die du selbst hochfährst, kein fremder Scope, den du respektieren musst. Nutze es, um neue Techniken zu lernen, bevor du sie auf ein echtes Programm anwendest.

root@kitploit:~
cd legacy-vm-practice
./scripts/setup_network.sh   # requires sudo
./scripts/download_vms.sh
./scripts/start_lab.sh
./scripts/verify_lab.sh

Siehe legacy-vm-practice/README.md und legacy-vm-practice/docs/quickstart.md.


Projektstruktur

root@kitploit:~
bugbounty-lab/
│
├── README.md                       # This file — overview + usage guide
│
├── programs/                       # Scope tracker: one .md per H1 program
│   ├── README.md
│   └── _template.md
│
├── bugbounty/                      # Core bug bounty engine
│   ├── bugbounty-hunter.sh         # scope/new/recon/vuln/brute/secrets/api/report
│   ├── QUICK-REFERENCE.md          # Commands, payloads, bounty by severity
│   ├── templates/report-template.md
│   └── reports/<target>/           # Output per phase + final report
│
├── auto-scanner/                   # Generic arsenal (400+ tools, not H1-specific)
│   ├── pentest.sh                  # Unified command (incl. `pentest.sh bounty ...`)
│   ├── tools/registry.sh
│   ├── burp-integration/
│   └── reports/
│
├── docs/
│   ├── hackerone-workflow.md       # H1 methodology: choose program, dedup, quality
│   ├── ai-assisted-code-review.md  # AI-assisted code/JS review
│   ├── known-cve-watchlist.md      # Most reported CVEs in Hacktivity
│   ├── known-cwe-watchlist.md      # Most reported vuln classes in Hacktivity
│   └── recursos/learning-resources.md
│
└── legacy-vm-practice/             # Classic VM lab (DVWA, Metasploitable...)

Wichtige Regeln

  1. Scanne niemals ein Asset, das nicht als In Scope in programs/<program>.md dokumentiert ist. Alle aktiven Scanner blockieren es, und es gibt keinen FORCE-Bypass.
  2. Respektiere die Ausschlüsse und Sonderregeln jedes Programms (Rate Limits, ausgeschlossene Schwachstellentypen, Testkonten).
  3. Prüfe vor dem Reporting auf Duplikate in Hacktivity.
  4. Führe keine destruktiven Aktionen gegen echte Ziele aus — siehe Checkliste in bugbounty/templates/report-template.md.
  5. legacy-vm-practice/ gehört dir: private IPs, die du selbst hochfährst, kein fremder Scope. Nutze es, um neue Techniken zu lernen.

Fehlerbehebung

bugbounty-hunter.sh meldet "No scope file" Führe ./bugbounty-hunter.sh new <program> aus und füge die Domain zum Abschnitt ## In Scope der generierten Datei in programs/ hinzu.

Fehlende Tools (subfinder, nuclei, httpx usw.)

root@kitploit:~
./auto-scanner/pentest.sh install

VM-Lab startet nicht Siehe Fehlerbehebung in legacy-vm-practice/README.md (Host-Only Adapter, NAT, Firewall).


Lernressourcen

RessourceSchwerpunkt
Hacker101CTFs + HackerOne-Videos, Badges für private Programme
HackerOne HacktivityÖffentliche Reports — Qualität studieren und Duplikate vermeiden
HackerOne DirectoryProgramm nach Scope und Response-Statistiken auswählen
PortSwigger Web Security AcademyTechnische Grundlagen von Web-Schwachstellen

Vollständige Liste unter docs/recursos/learning-resources.md.


Disclaimer

root@kitploit:~
╔══════════════════════════════════════════════════════════════════════════════╗
║                                                                              ║
║  WARNING                                                                     ║
║                                                                              ║
║  This lab is designed for AUTHORIZED bug bounty via HackerOne.               ║
║                                                                              ║
║  Only test assets within the program's published scope                       ║
║  bugbounty-hunter.sh blocks targets without documented scope in programs/    ║
║  Unauthorized use of these tools is ILLEGAL                                  ║
║  Respect each program's exclusions and special rules                         ║
║  Always use these tools ETHICALLY and RESPONSIBLY                            ║
║                                                                              ║
╚══════════════════════════════════════════════════════════════════════════════╝

Arsenal-Statistiken

root@kitploit:~
┌─────────────────────────────────────────────────────────────────┐
│                                                                 │
│   RECON              200+ tools   ████████████████ 100%         │
│   ENUMERATION         60+ tools   ██████████░░░░░░  60%         │
│   WEB                 20+ tools   ████░░░░░░░░░░░░  20%         │
│   EXPLOITATION        80+ tools   ████████████████  80%         │
│   POST-EXPLOIT        50+ tools   ████████████░░░░  60%         │
│                                                                 │
│   TOTAL: 400+ categorized tools                                 │
│                                                                 │
└─────────────────────────────────────────────────────────────────┘

Changelog

Die vollständige Liste der Änderungen findest du in CHANGELOG.md.


root@kitploit:~
+=============================================================+
|                                                             |
|   Bug Bounty Lab  •  HackerOne  •  400+ Tools               |
|                                                             |
+=============================================================+

Viel Erfolg bei der Jagd.

Tool herunterladen