Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
bug-bounty-library — Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and prior-art review. | Kitploit
工具/GitLabGitLab/wattocyber/bug-bounty-library
ReconnaissanceVulnerability AnalysisWeb SecurityFuzzingPenetration TestingSubdomain EnumerationLearning & EducationCurated ResourcesLearning Paths & Courses
GitLabwattocyber/bug-bounty-library

bug-bounty-library

Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and prior-art review.

919天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库网站
内容在请求的语言中不可用。显示英文版本。

Bug Bounty / Original Findings Library

Bug Bounty Notes banner

license gitlab

Folders are numbered in the order a hunter actually works - first to last.

Start at 00-hunt/00-INDEX. Run the hunt from 00-hunt/ALPHA. This README is only the map.

Authorization only. Safe harbor, VDP, GitHub PVR, or coordinated disclosure. No other-customer data. No exploit recipes.

First → last

#FolderWhat you do hereDo not skip to
000-hunt/00-INDEXOpen the instruction book. Copy the Target Card.Class playbooks
101-authorize/00-INDEXQuote the policy. Pick a lane. Classify. Score. Walk away if <8.Recon on a brochure
202-recon/00-INDEXName in-scope hosts, operations, JS, schemas.Testing a host you have not named
303-prior-art/00-INDEXBuild the packet before deep work.“I’ll check Hacktivity later”
404-map/00-INDEXActor × action × object × tenant × state.Confirming an unnamed cell
505-test/00-INDEXOnly the stack. Order inside is hunter-ROI, not OWASP. Every leftover class: 05-test/00-WATCH-ATLAS.The whole index
606-confirm-report/00-INDEXOwned-fixture confirm → uniqueness gate → one ticket → ledger.Submit to “see what triage says”
707-writeups/00-INDEXDistilled cards (methods, not copies).Hunting from a blog
808-tools/READMERead-only CLIs.Live Nuclei
9

Narrative companion (market + resume): BOOK-Original-Findings-Playbook. Not the runbook.

Commands ALPHA calls

root@kitploit:~
python3 tools/classify_target.py --intake out/target-card.yaml -o out/stack.yaml
python3 tools/target_score.py --intake out/target-card.yaml
python3 tools/crt_enum.py --intake out/target-card.yaml -o out/crt-names.txt
python3 tools/prior_art_desk.py --product "…" --repo "owner/name" -o out/prior-art.md
python3 tools/catalog_query.py --q "…" --year 2025 --sort bounty --limit 25
python3 tools/object_graph_stub.py --schema schema.graphql -o out/matrix.csv

Copy 00-hunt/templates/target-card.example to out/target-card.yaml. Hunt only if target_score.py prints ≥10.

This repo is the library only (extracted from WattoCyber/oscp-notes-2026). Known-CVE feeds are GHSA / OSV / NVD via tools/prior_art_desk.py, not a submission queue.

Repo: https://gitlab.com/WattoCyber/bug-bounty-library

下载工具
09-prompts/00-INDEX
Extract / reject / structure.
Exploit prompts
1010-checklists/intakePrintable one-pagers.A third spine
1111-theory/00-INDEXWhy the spine exists.Hunting from theory