Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Bug-Bounty — Bug Bounty ~ Awesomes | Books | Cheatsheets | Checklists | Tools | Wordlists | More | Kitploit
工具/GitHubGitHub/anlominus/bug-bounty
ReconnaissanceVulnerability AnalysisWeb SecurityCTFPenetration TestingLearning & EducationCurated ResourcesLabs & Practice
GitHubanlominus/bug-bounty

Bug-Bounty

Bug Bounty ~ Awesomes | Books | Cheatsheets | Checklists | Tools | Wordlists | More

查看仓库
6511089个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

בס״ד

⚜️ Aภl๏miuภuຮ ⚜️

⫷ HacKingPro ⫸
⫷ TryHackMe | KoTH ⫸
⫷ Privilege-Escalation⫸
⫷ ScanPro | Linfo | Diablo ⫸
⫷ Offensive-Security | PenTest ⫸
⫷ Goals | Studies | HacKing | AnyTeam ⫸

image


漏洞赏金

  • 精选资源
  • 书籍
  • 速查表
  • 检查清单
  • 工具
  • 字典
  • 更多

GitHub Bounty

GitHub Security Bug Bounty

软件安全研究人员越来越多地与互联网公司合作以寻找漏洞。

我们的漏洞赏金计划向这些研究人员致敬,并为严重漏洞提供 30,000 美元或更多的奖励。

精选资源

  • Awesome Bug Bounty Tools

    精选的各种漏洞赏金工具列表

    https://github.com/vavkamil/awesome-bugbounty-tools

  • Awesome Bug Bounty

    来自漏洞赏金猎人的漏洞赏金计划与 write-up 的全面精选列表。

  • Awesome CTF

    精选的 () 框架、库、资源、软件和教程列表。该列表旨在帮助新手和经验丰富的 CTF 玩家在一个地方找到与 CTF 相关的所有内容。


书籍

  • Hacking-Books 以下是一些流行的黑客技术 PDF

  • The Threat Hunter Playbook ~ The Threat Hunter Playbook

  • image

    The Threat Hunter Playbook 是一个社区驱动的开源项目,旨在分享检测逻辑、对手战术和资源,使检测开发更加高效。该项目中的所有检测文档都遵循 MITRE ATT&CK 的结构,将入侵后的对手行为按战术分组进行分类,并以交互式笔记本的形式提供。使用笔记本不仅让我们能够分享文本、查询和预期输出,还能分享代码,帮助他人在本地或通过 BinderHub 云计算环境远程对预先记录的安全数据集运行检测逻辑。


速查表

  • Bug Bounty Cheat Sheet

    面向漏洞赏金猎人的有趣 payload、提示和技巧列表。

  • Bug Bounty Cheat Sheet

    面向漏洞赏金猎人的有趣 payload、提示和技巧列表。


检查清单

  • Galaxy-Bugbounty-Checklist

    漏洞赏金和渗透测试的提示与教程。


工具

  • Bug Bounty Methodology & Tools

以下是我们仅在 Twitch 上进行被动实时侦察时使用的一些工具:

  1. Recon-ng https://github.com/lanmaster53/recon-ng
  2. httpx https://github.com/projectdiscovery/httpx
  3. isup.sh https://github.com/gitnepal/isup
  4. Arjun https://github.com/s0md3v/Arjun
  5. jSQL https://github.com/ron190/jsql-injection
  6. Smuggler https://github.com/defparam/smuggler
  7. Sn1per https://github.com/1N3/Sn1per
  8. Spiderfoot https://github.com/smicallef/spiderfoot
  9. Nuclei https://github.com/projectdiscovery/nuclei
  10. Jaeles https://github.com/jaeles-project/jaeles
  11. ChopChop https://github.com/michelin/ChopChop
  12. Inception https://github.com/proabiral/inception
  13. Eyewitness https://github.com/FortyNorthSecurity/EyeWitness
  14. Meg https://github.com/tomnomnom/meg
  15. Gau - 获取所有 URL https://github.com/lc/gau
  16. Snallygaster https://github.com/hannob/snallygaster
  17. NMAP https://github.com/nmap/nmap
  18. Waybackurls https://github.com/tomnomnom/waybackurls
  19. Gotty https://github.com/yudai/gotty
  20. GF https://github.com/tomnomnom/gf
  21. GF Patterns
  • BugDog

    一个强大的漏洞狩猎工具。支持 SQL、XSS、PHP 代码执行、SSRF……我已将我自己的 payload 添加到其中,这些 payload 是我在漏洞狩猎期间发现的。其余部分,你也可以添加你的自定义 payload ;)

    image

    • 注意:BugDog 是用 python 编写的,需要 python2 才能完美运行。

  • Bug-Bounty-Tools: 用于漏洞赏金的随机工具

  • BigBountyRecon

    BigBountyRecon 工具利用 58 种不同的技术,结合各种 Google dorks 和开源工具来加速对目标组织的初始侦察过程。


字典

  • Bug-Bounty-Wordlists

    一个包含漏洞狩猎期间使用的所有重要字典的仓库。

  • a-full-list-of-wordlists

    这里包含 burp pack

  • FuzzDB

    FuzzDB 旨在通过动态应用程序安全测试提高发现应用程序安全漏洞的可能性。它是第一个也是最全面的开源字典,包含故障注入模式、可预测的资源位置以及用于匹配服务器响应的正则表达式。

  • wordlist-tools

    一套让字典使用更轻松的工具


更多

  • The Bug Hunter's Methodology (TBHM)

    与 Web 应用程序安全评估相关,更具体地说是针对漏洞赏金中的漏洞狩猎。

  • Galaxy-Bugbounty-Checklist:

    漏洞赏金和渗透测试的提示与教程。

  • HowToHunt

    漏洞狩猎期间的教程和要做的事情。

  • Awesome-Bugbounty-Writeups

    精选的漏洞赏金 writeup 列表(按漏洞类型分类),灵感来自 https://github.com/ngalongc/bug-bounty-reference


^ 返回顶部 ^

下载工具
Capture The Flag
CTF
  • Awesome Bug Bounty Builder

    Awesome Bug bounty builder 项目 - 查找漏洞所需的所有常用工具。

    image

  • https://github.com/1ndianl33t/Gf-Patterns
  • Paramspider https://github.com/devanshbatham/ParamSpider
  • XSSER https://github.com/epsylon/xsser
  • UPDOG https://github.com/sc0tfree/updog
  • JSScanner https://github.com/dark-warlord14/JSScanner
  • Takeover https://github.com/m4ll0k/takeover
  • Keyhacks https://github.com/streaak/keyhacks
  • S3 Bucket AIO Pwn https://github.com/blackhatethicalhacking/s3-buckets-aio-pwn
  • BHEH Sub Pwner Recon https://github.com/blackhatethicalhacking/bheh-sub-pwner
  • GitLeaks https://github.com/zricethezav/gitleaks
  • Domain-2IP-Converter https://github.com/blackhatethicalhacking/Domain2IP-Converter
  • Dalfox https://github.com/hahwul/dalfox
  • Log4j Scanner https://github.com/Black-Hat-Ethical-Hacking/log4j-scan
  • Osmedeus https://github.com/j3ssie/osmedeus
  • getJS https://github.com/003random/getJS
    • image
  • Hack-Pet:

    hack-pet 是一系列对黑客/漏洞赏金猎人有用的命令片段集合。

    它与 recon_profile 类似,但它使用 pet。pet 可以更高效地管理命令集。

    image
    image

  • CTF-tool

    精选的 Capture The Flag (CTF) 框架、库、资源和软件列表。

  • Bug bounty toolkit

    在这里你可以找到一份在漏洞赏金或渗透测试中使用的不同工具列表。

    一些类别和工具会随着我们的进展而添加。

    如果你有任何问题或建议,请随时在 twitter 上联系我 (https://twitter.com/_sehno_)

  • BugHuntingToolKit

    这是为漏洞猎人打造的一个工具,我在其中收录了漏洞猎人使用的工具

  • Parrots Recon

    面向漏洞赏金的侦察自动化

  • OK-VPS

    image

    漏洞赏金 VPS 设置工具安装程序

    使用这些工具,你可以通过一条命令安装大多数漏洞赏金工具。该工具已被修改并收录了许多工具 ## 特别感谢 @supr4s,因为其中大部分工具都是基于他的工具修改的

  • kali-repos

    用于漏洞赏金和 CTF 的 Kali Linux 容器

  • Bot-Bounty

    这是一个专为渗透测试和漏洞赏金构建的 Telegram Bot Python 脚本。它就像一个 telegram shell。

    当你的任务(命令行)完成并产生结果时,你会收到通知。这个机器人可以替你处理长时间运行的任务,任务完成后你无需再保持关注。

    image
    image

  • 子域名侦察

    • amass
    • subfinder
    • assetfinder
    • dnsgen
    • shuffledns
    • httprobe
    • aquatone
  • 手动侦察

    • shodan
    • censys
    • google dorks
    • pastebin
    • github
  • 枚举 / 爬取

    • nmap
    • ffuf
    • hakrawler
    • gau
    • paramspider
    • arjun
    • parameth
  • XSS

    • xsshunter
    • xsscrapy
    • dalfox
  • SQL 注入

    • sqlmap
    • waybacksqliscanner
  • AllAboutBugBounty

    关于漏洞赏金的一切(绕过技巧、payload 等)

  • HolyTips

    关于漏洞赏金狩猎和 Web 应用程序安全的笔记、检查清单和 writeup 合集。

  • KingOfBugBountyTips

    我们的主要目标是分享一些知名漏洞猎人的技巧。利用侦察方法论,我们能够发现已经可利用的子域名、API 和令牌,从而进行报告。我们希望影响 Onelinetips 并解释这些命令,以便新手猎人更好地理解。

  • Resources-for-Beginner-Bug-Bounty-Hunters:

    为那些有兴趣开始参与漏洞赏金的人提供的资源列表

    目录

    • 基础知识
    • 环境搭建
    • 工具
    • 实验室与测试环境
    • 演讲
    • 漏洞类型
    • 移动端渗透测试
    • 智能合约
    • 编码与脚本
    • 硬件与物联网
    • 博客文章与演讲
    • 媒体资源
    • 认证
    • 心态与心理健康