
awesome-bugbounty-tools
Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

Real-world infosec wordlists, updated regularly

Curated, continuously validated list of reliable DNS resolvers for DNS enumeration, reconnaissance, and bug bounty workflows.

🕵️♂️ All-in-one OSINT tool for analysing any website

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

A collection of scripts for assessing Microsoft Azure security

Checklists and templates for bug bounty programs. MIT licensed.

ReconHound is a Python-based web reconnaissance tool designed for penetration testers, bug bounty hunters, and ethical hackers. It supports directory…

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

A curated collection of tools, techniques, frameworks, and learning resources focused on Attack Surface Management (ASM).

Nuclei Templates Collection

Curated collection of wordlists for bug bounty hunting, covering directories, subdomains, parameters, usernames, passwords, and web fuzzing payloads.

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

This Repositories contains list of One Liners with Descriptions and Installation requirements

Modular subdomain enumeration suite with certificate transparency, DNS brute-force, and API-based discovery. Includes post-enumeration modules for…

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Domains belonging to the most reputed public bug bounty programs. [NOT FOR NON-MONETARY OR PRIVATE PROGRAMS]