Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
bug-bounty-library — Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and prior-art review. | Kitploit
Strumenti/GitLabGitLab/wattocyber/bug-bounty-library
ReconnaissanceVulnerability AnalysisWeb SecurityFuzzingPenetration TestingSubdomain EnumerationLearning & EducationCurated ResourcesLearning Paths & Courses

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
GitLabwattocyber/bug-bounty-library

bug-bounty-library

Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and prior-art review.

Vedi RepositorySito web
819 giorni faNon ancora revisionato
Condividi
Contenuto non disponibile nella lingua richiesta. Visualizzazione della versione inglese.

Bug Bounty / Original Findings Library

Bug Bounty Notes banner

license gitlab

Folders are numbered in the order a hunter actually works - first to last.

Start at 00-hunt/00-INDEX. Run the hunt from 00-hunt/ALPHA. This README is only the map.

Authorization only. Safe harbor, VDP, GitHub PVR, or coordinated disclosure. No other-customer data. No exploit recipes.

First → last

#FolderWhat you do hereDo not skip to
000-hunt/00-INDEXOpen the instruction book. Copy the Target Card.Class playbooks
101-authorize/00-INDEXQuote the policy. Pick a lane. Classify. Score. Walk away if <8.Recon on a brochure
202-recon/00-INDEXName in-scope hosts, operations, JS, schemas.Testing a host you have not named
303-prior-art/00-INDEXBuild the packet before deep work.“I’ll check Hacktivity later”
404-map/00-INDEXActor × action × object × tenant × state.Confirming an unnamed cell
505-test/00-INDEXOnly the stack. Order inside is hunter-ROI, not OWASP. Every leftover class: 05-test/00-WATCH-ATLAS.The whole index
606-confirm-report/00-INDEXOwned-fixture confirm → uniqueness gate → one ticket → ledger.Submit to “see what triage says”
707-writeups/00-INDEXDistilled cards (methods, not copies).Hunting from a blog
808-tools/READMERead-only CLIs.Live Nuclei
9

Narrative companion (market + resume): BOOK-Original-Findings-Playbook. Not the runbook.

Commands ALPHA calls

root@kitploit:~
python3 tools/classify_target.py --intake out/target-card.yaml -o out/stack.yaml
python3 tools/target_score.py --intake out/target-card.yaml
python3 tools/crt_enum.py --intake out/target-card.yaml -o out/crt-names.txt
python3 tools/prior_art_desk.py --product "…" --repo "owner/name" -o out/prior-art.md
python3 tools/catalog_query.py --q "…" --year 2025 --sort bounty --limit 25
python3 tools/object_graph_stub.py --schema schema.graphql -o out/matrix.csv

Copy 00-hunt/templates/target-card.example to out/target-card.yaml. Hunt only if target_score.py prints ≥10.

This repo is the library only (extracted from WattoCyber/oscp-notes-2026). Known-CVE feeds are GHSA / OSV / NVD via tools/prior_art_desk.py, not a submission queue.

Repo: https://gitlab.com/WattoCyber/bug-bounty-library

Scarica lo strumento
09-prompts/00-INDEX
Extract / reject / structure.
Exploit prompts
1010-checklists/intakePrintable one-pagers.A third spine
1111-theory/00-INDEXWhy the spine exists.Hunting from theory