Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
bugbounty-lab101 — Un workspace completo per bug bounty per ricercatori HackerOne. Include l'applicazione dello scope, una pipeline automatizzata di recon/vuln (oltre 400 strumenti), template di report, watchlist CVE/CWE e un laboratorio VM locale per la pratica. Progettato per una caccia disciplinata ed etica. | Kitploit
Strumenti/GitHubGitHub/devcop95/bugbounty-lab101
RicognizioneScanner di VulnerabilitàScanner di Vulnerabilità WebScripting e AutomazioneSfruttamento di Applicazioni WebTest di Sicurezza delle APIRaccolta InformazioniPenetration Testing

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Enumerazione Sottodomini
Apprendimento e Formazione
Lab e Pratica
GitHubdevcop95/bugbounty-lab101

bugbounty-lab101

Vedi Repository
4117231 mese faRevisionato da Kitploit

Informazioni

Un workspace completo per bug bounty per ricercatori HackerOne. Include l'applicazione dello scope, una pipeline automatizzata di recon/vuln (oltre 400 strumenti), template di report, watchlist CVE/CWE e un laboratorio VM locale per la pratica. Progettato per una caccia disciplinata ed etica.

Condividi
root@kitploit:~
          ██████╗ ███████╗██╗   ██╗ ██╗ ██████╗  ██╗██╗  ██╗
          ██╔══██╗██╔════╝██║   ██║███║██╔═████╗███║╚██╗██╔╝
          ██║  ██║█████╗  ██║   ██║╚██║██║██╔██║╚██║ ╚███╔╝
          ██║  ██║██╔══╝  ╚██╗ ██╔╝ ██║████╔╝██║ ██║ ██╔██╗
          ██████╔╝███████╗ ╚████╔╝  ██║╚██████╔╝ ██║██╔╝ ██╗
          ╚═════╝ ╚══════╝  ╚═══╝   ╚═╝ ╚═════╝  ╚═╝╚═╝  ╚═╝

BUG BOUNTY LAB

Workspace Bug Bounty per Ricercatori HackerOne

Stars Forks License HackerOne

Kali Linux
Tools
Scope Safe

Indice

  • Cos'è questo?
  • Avvio rapido
  • T3MP3ST — War Room basata su AI
  • Comandi principali
  • Matrice degli strumenti per fase
  • Strumenti per categoria
  • Esempio di report
  • Workflow
  • Esercitarsi senza toccare programmi reali
  • Struttura del progetto
  • Regole importanti
  • Risoluzione dei problemi
  • Risorse di apprendimento
  • Changelog

Cos'è questo?

Un workspace costruito attorno al workflow reale del bug bounty su HackerOne: scegli un programma, documenta lo scope, scansiona entro i limiti, concatena le vulnerabilità e redigi il report in un formato che i triager accettano rapidamente. L'arsenale generico di oltre 400 strumenti di pentesting e il laboratorio VM locale sono disponibili come supporto — non come punto di partenza.

root@kitploit:~
┌─────────────────────────────────────────────────────────────────────┐
│                                                                     │
│  SCOPE                RECON/VULN              REPORT                │
│  ═════                ══════════              ══════                │
│                                                                     │
│  ┌───────────┐      ┌───────────────────┐    ┌───────────────┐      │
│  │programs/  │────▶  bugbounty-hunter   ───▶  report.md     │      │
│  │*.md       │      │      .sh          │    │ (H1 template) │      │
│  └───────────┘      └────────┬──────────┘    └───────┬───────┘      │
│  scope check                 │                       │              │
│  (blocks if not              ▼                       ▼              │
│   documented)       ┌─────────────┐         ┌──────────────┐        │
│                     │auto-scanner │         │  Hacktivity  │        │
│                     │ (arsenal)   │         │  dedup check │        │
│                     └─────────────┘         └──────────────┘        │
│                                                                     │
└─────────────────────────────────────────────────────────────────────┘

Avvio rapido

1. Permessi

root@kitploit:~
cd bugbounty-lab101
chmod +x bugbounty/*.sh auto-scanner/*.sh
# If the repository was cloned without submodules:
git submodule update --init --recursive

2. Documenta lo scope del programma

root@kitploit:~
cd bugbounty
./bugbounty-hunter.sh new program-name
# Edit ../programs/program-name.md with the EXACT scope from the H1 policy

3. Verifica lo scope e scansiona

root@kitploit:~
./bugbounty-hunter.sh scope target.com     # must say "Scope OK" before proceeding
./bugbounty-hunter.sh full target.com       # recon -> vuln -> brute -> secrets -> api -> report

4. Report

root@kitploit:~
./bugbounty-hunter.sh report target.com
# Complete bugbounty/reports/target.com/report-YYYYMMDD.md with the H1 template

Prima di inviare, leggi docs/hackerone-workflow.md (dedup su Hacktivity, qualità del report, passi successivi all'invio).


T3MP3ST — War Room basata su AI

Questo laboratorio integra T3MP3ST come motore di sicurezza offensiva — un framework multi-agente che trasforma il tuo agente di coding AI in un cacciatore di zero-day.

Configurazione

root@kitploit:~
# 1. Clone T3MP3ST into the lab (it's .gitignored, separate repo)
git clone https://github.com/DevCop95/T3MP3ST t3mp3st
cd t3mp3st && npm install && cd ..

# 2. Configure API keys
cp t3mp3st/.env.example t3mp3st/.env
# Edit t3mp3st/.env with your LLM provider key(s)

# 3. Start the server
./start-server.sh
# War Room → http://127.0.0.1:3333/ui/

Cosa offre T3MP3ST

FunzionalitàDescrizione
War Room UIInterfaccia web per la pianificazione e l'esecuzione delle missioni
Recon Enginenmap, DNS, fingerprinting HTTP — 90.1% pass@1 su XBEN
Exploit LoopKill chain a 8 operatori (Recon → Scanner → Exploiter → ...)
Payload DBOltre 200 payload (SQLi, XSS, SSTI, LFI, SSRF, CMDi, XXE)
MCP Servernode t3mp3st/dist/mcp-server.js per l'integrazione con l'agente
Evidence VaultFindings persistenti, evidenze e tracciamento dei retest

Modalità keyless

T3MP3ST funziona senza API key collegando il tuo agente AI locale (Claude Code, Codex, Hermes). Nell'interfaccia War Room, apri Settings e collega il tuo agente — poi descrivi i target in linguaggio naturale.


Comandi principali

ComandoDescrizioneEsempio
bugbounty-hunter.sh new <prog>Crea un tracker di scope per un programma./bugbounty-hunter.sh new acme-corp
bugbounty-hunter.sh scope <target>Verifica che il target sia nello scope./bugbounty-hunter.sh scope target.com
bugbounty-hunter.sh full <target>Pipeline completa (da recon a report)./bugbounty-hunter.sh full target.com
bugbounty-hunter.sh recon <target>Solo recon, incluso l'arricchimento passivo Shodan CTL./bugbounty-hunter.sh recon target.com
bugbounty-hunter.sh report <target>Genera il report con il template H1./bugbounty-hunter.sh report target.com
pentest.sh <url>Arsenale generico (oltre 400 strumenti)pentest.sh https://target.com
pentest.sh matrixMatrice completa degli strumentipentest.sh matrix
pentest.sh search <function>Cerca uno strumentopentest.sh search sql_injection
pentest.sh express <url>Scansione expresspentest.sh express https://target.com
pentest.sh installInstalla gli strumenti mancantipentest.sh install
./start-server.shAvvia la War Room T3MP3ST (basata su AI)./start-server.sh
npm run serverAvvia T3MP3ST dalla directory t3mp3st/cd t3mp3st && npm run server

Tutti i comandi di scansione attiva in bugbounty-hunter.sh verificano lo scope rispetto a programs/*.md prima di toccare il target. L'integrazione passiva Shodan CTL è opzionale e utilizza il submodule bloccato vendor/shodan_reconsx quando recons101x non è installato. I suoi hostname vengono filtrati per scope prima di qualsiasi probing HTTP.


Matrice degli strumenti per fase

root@kitploit:~
╔═════════════════════════════════════════════════════════════════════════╗
║                                                                         ║
║  PHASE 1          PHASE 2          PHASE 3          PHASE 4             ║
║  RECON            SCANNING         ENUMERATION      EXPLOITATION        ║
║                                                                         ║
║  ┌───────────┐   ┌───────────┐   ┌───────────┐   ┌───────────┐          ║
║  │   nmap    │─▶   nikto     ──▶  enum4l     ──▶  sqlmap              
║  │   amass   │   │ gobuster  │   │  smbclnt  │   │metasploit │          ║
║  │   dig     │   │  whatweb  │   │  ldapsrc  │   │  xsser    │          ║
║  │   whois   │   │   wfuzz   │   │  rpcclnt  │   │  wpscan   │          ║
║  └───────────┘   └───────────┘   └───────────┘   └───────────┘          ║
║        │              │               │               │                 ║
║        ▼              ▼               ▼               ▼                 ║
║  ┌───────────┐   ┌───────────┐   ┌───────────┐   ┌───────────┐          ║
║  │  theHarv  │   │   dirb    │   │ snmpwalk  │   │ msfvenom  │          ║
║  │  recon-ng │   │   ffuf    │   │  nbtscan  │   │ searchsp  │          ║
║  └───────────┘   └───────────┘   └───────────┘   └───────────┘          ║
║                                                                         ║
╠═════════════════════════════════════════════════════════════════════════╣
║                                                                         ║
║  PHASE 5          PHASE 6          PHASE 7          PHASE 8             ║
║  BUSINESS LOGIC   API TESTING      CHAIN ATTACKS    REPORT              ║
║                                                                         ║
║  ┌───────────┐   ┌───────────┐   ┌───────────┐   ┌───────────┐          ║
║  │auth flow  │   │  swagger  │   │CORS+CSRF  │   │    H1     │          ║
║  │race cond  │   │  graphql  │   │SSRF+RCE   │   │  REPORT   │          ║
║  │mass assn  │   │  nuclei   │   │IDOR+priv  │   │   .md     │          ║
║  └───────────┘   └───────────┘   └───────────┘   └───────────┘          ║
║                                                                         ║
╚═════════════════════════════════════════════════════════════════════════╝

Strumenti per categoria (auto-scanner/ — arsenale di supporto)

Ricognizione (oltre 50 strumenti)

root@kitploit:~
┌────────────────────────────────────────────────────────────────┐
│  NETWORK SCANNING:                                             │
│  nmap        masscan      zmap         unicornscan             │
│  netdiscover                                                   │
│                                                                │
│  DNS ENUMERATION:                                              │
│  dnsrecon    dig          host         dnsenum                 │
│  dnsmap      sublist3r    subfinder    subbrute                │
│  dnsgen      gotator      fierce       dnspoodle               │
│                                                                │
│  HTTP RECON:                                                   │
│  httpx       httprobe     gau          waybackurls             │
│  katana      gospider     hakrawler    linkfinder              │
│  jsfinder    secretfinder paramspider  arjun                   │
│                                                                │
│  CLOUD RECON:                                                  │
│  s3scanner   cloud_enum   lazys3       bucket_finder           │
│                                                                │
│  SUBDOMAIN TAKEOVER:                                           │
│  subjack     subover      nuclei       canari                  │
└────────────────────────────────────────────────────────────────┘

Web (oltre 20 strumenti)

root@kitploit:~
┌─────────────────────────────────────────────────────────────────┐
│  SCANNERS:        nikto  whatweb  wapiti  arachni  skipfish     │
│  DIRECTORY BRUTE: gobuster  dirb  feroxbuster  dirsearch        │
│  FUZZING:         wfuzz  ffuf  arjun  x8  paramspider           │
│  VULNERABILITIES: sqlmap  xsser  dalfox  commix  xsstrike       │
│  CMS:             wpscan  joomscan  droopescan  cmseek  cariddi │
└─────────────────────────────────────────────────────────────────┘

Esempio di report (formato HackerOne)

root@kitploit:~
# Bug Bounty Report

## Platform
HackerOne

## Program
[program name]

## Researcher
[your-handle]

## Target
prime.example.com

## Weakness (H1 taxonomy)
CWE-538: Insertion of Sensitive Information into Externally-Accessible File

## Executive Summary
S3 bucket with listing enabled exposes N files without authentication,
including internal HR documents.

## Steps to Reproduce
1. curl -k https://prime.example.com/file-service/static/
2. ...

## Impact
[Concrete business impact, not generic]

Template completo in bugbounty/templates/report-template.md.


Workflow

root@kitploit:~
                      ┌─────────────────────┐
                      │  Choose H1 Program  │
                      └──────────┬──────────┘
                                 ▼
                      ┌─────────────────────┐
                      │ bugbounty-hunter.sh │
                      │   new <program>     │
                      └──────────┬──────────┘
                                 ▼
                      ┌─────────────────────┐
                      │  Document scope in  │
                      │   programs/*.md     │
                      └──────────┬──────────┘
                                 ▼
                ┌────────────────────────────────┐
                │ bugbounty-hunter.sh full <t>   │
                └────────────────┬───────────────┘
                                 │
              ┌──────────────────┼──────────────────┐
              ▼                  ▼                  ▼
       ┌──────────────┐   ┌──────────────┐   ┌──────────────┐
       │ RECON/VULN   │   │ MANUAL VERIF │   │ CHAIN ATTACK │
       │  (scripts)   │   │  (manual)    │   │  (manual)    │
       └──────┬───────┘   └──────┬───────┘   └──────┬───────┘
              └──────────────────┼──────────────────┘
                                 ▼
                      ┌─────────────────────┐
                      │  Dedup in Hacktivity│
                      └──────────┬──────────┘
                                 ▼
                      ┌─────────────────────┐
                      │  Submit H1 Report   │
                      └─────────────────────┘

Metodologia completa in docs/hackerone-workflow.md.


Esercitarsi senza toccare programmi reali

legacy-vm-practice/ è tuo: IP privati che avvii tu, nessuno scope di terze parti da rispettare. Usalo per imparare nuove tecniche prima di applicarle a un programma reale.

root@kitploit:~
cd legacy-vm-practice
./scripts/setup_network.sh   # requires sudo
./scripts/download_vms.sh
./scripts/start_lab.sh
./scripts/verify_lab.sh

Vedi legacy-vm-practice/README.md e legacy-vm-practice/docs/quickstart.md.


Struttura del progetto

root@kitploit:~
bugbounty-lab/
│
├── README.md                       # This file — overview + usage guide
│
├── programs/                       # Scope tracker: one .md per H1 program
│   ├── README.md
│   └── _template.md
│
├── bugbounty/                      # Core bug bounty engine
│   ├── bugbounty-hunter.sh         # scope/new/recon/vuln/brute/secrets/api/report
│   ├── QUICK-REFERENCE.md          # Commands, payloads, bounty by severity
│   ├── templates/report-template.md
│   └── reports/<target>/           # Output per phase + final report
│
├── auto-scanner/                   # Generic arsenal (400+ tools, not H1-specific)
│   ├── pentest.sh                  # Unified command (incl. `pentest.sh bounty ...`)
│   ├── tools/registry.sh
│   ├── burp-integration/
│   └── reports/
│
├── docs/
│   ├── hackerone-workflow.md       # H1 methodology: choose program, dedup, quality
│   ├── ai-assisted-code-review.md  # AI-assisted code/JS review
│   ├── known-cve-watchlist.md      # Most reported CVEs in Hacktivity
│   ├── known-cwe-watchlist.md      # Most reported vuln classes in Hacktivity
│   └── recursos/learning-resources.md
│
└── legacy-vm-practice/             # Classic VM lab (DVWA, Metasploitable...)

Regole importanti

  1. Non scansionare mai un asset che non sia documentato come In Scope in programs/<program>.md. Tutti gli scanner attivi lo bloccano e non esiste alcun bypass FORCE.
  2. Rispetta le esclusioni e le regole speciali di ogni programma (rate limit, tipi di vulnerabilità esclusi, account di test).
  3. Controlla la presenza di duplicati in Hacktivity prima di inviare il report.
  4. Non eseguire azioni distruttive contro target reali — vedi la checklist in bugbounty/templates/report-template.md.
  5. legacy-vm-practice/ è tuo: IP privati che avvii tu, nessuno scope di terze parti. Usalo per imparare nuove tecniche.

Risoluzione dei problemi

bugbounty-hunter.sh dice "No scope file" Esegui ./bugbounty-hunter.sh new <program> e aggiungi il dominio alla sezione ## In Scope del file generato in programs/.

Strumenti mancanti (subfinder, nuclei, httpx, ecc.)

root@kitploit:~
./auto-scanner/pentest.sh install

Il laboratorio VM non si avvia Vedi la risoluzione dei problemi in legacy-vm-practice/README.md (Host-Only Adapter, NAT, firewall).


Risorse di apprendimento

RisorsaFocus
Hacker101CTF + video HackerOne, badge per programmi privati
HackerOne HacktivityReport pubblici — studia la qualità ed evita i duplicati
HackerOne DirectoryScegli il programma in base a scope e statistiche di risposta
PortSwigger Web Security AcademyFondamenti tecnici delle vulnerabilità web

Elenco completo in docs/recursos/learning-resources.md.


Disclaimer

root@kitploit:~
╔══════════════════════════════════════════════════════════════════════════════╗
║                                                                              ║
║  WARNING                                                                     ║
║                                                                              ║
║  This lab is designed for AUTHORIZED bug bounty via HackerOne.               ║
║                                                                              ║
║  Only test assets within the program's published scope                       ║
║  bugbounty-hunter.sh blocks targets without documented scope in programs/    ║
║  Unauthorized use of these tools is ILLEGAL                                  ║
║  Respect each program's exclusions and special rules                         ║
║  Always use these tools ETHICALLY and RESPONSIBLY                            ║
║                                                                              ║
╚══════════════════════════════════════════════════════════════════════════════╝

Statistiche dell'arsenale

root@kitploit:~
┌─────────────────────────────────────────────────────────────────┐
│                                                                 │
│   RECON              200+ tools   ████████████████ 100%         │
│   ENUMERATION         60+ tools   ██████████░░░░░░  60%         │
│   WEB                 20+ tools   ████░░░░░░░░░░░░  20%         │
│   EXPLOITATION        80+ tools   ████████████████  80%         │
│   POST-EXPLOIT        50+ tools   ████████████░░░░  60%         │
│                                                                 │
│   TOTAL: 400+ categorized tools                                 │
│                                                                 │
└─────────────────────────────────────────────────────────────────┘

Changelog

Vedi CHANGELOG.md per l'elenco completo delle modifiche.


root@kitploit:~
+=============================================================+
|                                                             |
|   Bug Bounty Lab  •  HackerOne  •  400+ Tools               |
|                                                             |
+=============================================================+

Buona caccia.

Scarica lo strumento