Bugbounty Open Source Projects

Browse 472 Bugbounty open source projects, ranked by GitHub stars. Find the most popular Bugbounty tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 472 projects
14,521 stars

maurosoria/dirsearch

Web path scanner

Metrics details
Stars14,521
14,043 stars

projectdiscovery/subfinder

Fast passive subdomain enumeration tool.

Metrics details
Stars14,043
12,654 stars

projectdiscovery/nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Metrics details
Stars12,654
12,119 stars

nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters

A list of resources for those interested in getting started in bug bounties

Metrics details
Stars12,119
11,908 stars

dstotijn/hetty

An HTTP toolkit for security research.

Metrics details
Stars11,908
10,921 stars

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Metrics details
Stars10,921
10,189 stars

blacklanternsecurity/bbot

The recursive internet scanner for hackers. 🧡

Metrics details
Stars10,189
10,184 stars

projectdiscovery/httpx

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

Metrics details
Stars10,184
9,932 stars

shmilylty/OneForAll

OneForAll是一款功能强大的子域收集工具

Metrics details
Stars9,932
9,601 stars

OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Metrics details
Stars9,601
8,746 stars

yogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

Metrics details
Stars8,746
7,866 stars

six2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Metrics details
Stars7,866
7,160 stars

KathanP19/HowToHunt

Collection of methodology and test case for various web vulnerabilities.

Metrics details
Stars7,160
6,809 stars

daffainfo/AllAboutBugBounty

All about bug bounty (bypasses, payloads, and etc)

Metrics details
Stars6,809
6,678 stars

ihebski/DefaultCreds-cheat-sheet

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Metrics details
Stars6,678
6,513 stars

EdOverflow/bugbounty-cheatsheet

A list of interesting payloads, tips and tricks for bug bounty hunters.

Metrics details
Stars6,513
6,484 stars

j3ssie/osmedeus

A Modern Orchestration Engine for Security

Metrics details
Stars6,484
6,366 stars

reddelexc/hackerone-reports

Top disclosed reports from HackerOne

Metrics details
Stars6,366
6,170 stars

dwisiswant0/apkleaks

Scanning APK file for URIs, endpoints & secrets.

Metrics details
Stars6,170
6,145 stars

GhostTroops/scan4all

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

Metrics details
Stars6,145
6,125 stars

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Metrics details
Stars6,125
6,034 stars

devanshbatham/Awesome-Bugbounty-Writeups

A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference

Metrics details
Stars6,034
5,787 stars

commixproject/commix

Automated All-in-One OS Command Injection Exploitation Tool

Metrics details
Stars5,787
5,755 stars

EdOverflow/can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Metrics details
Stars5,755
5,182 stars

payloadbox/xss-payload-list

🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List

Metrics details
Stars5,182
5,130 stars

hahwul/dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

Metrics details
Stars5,130
5,091 stars

hakluke/hakrawler

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Metrics details
Stars5,091
4,905 stars

hahwul/WebHackersWeapons

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Metrics details
Stars4,905
4,502 stars

TophantTechnology/ARL

ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。

Metrics details
Stars4,502
4,448 stars

projectdiscovery/interactsh

An OOB interaction gathering server and client library

Metrics details
Stars4,448
4,113 stars

jonaslejon/malicious-pdf

💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh

Metrics details
Stars4,113
3,966 stars

payloadbox/sql-injection-payload-list

🎯 SQL Injection Payload List

Metrics details
Stars3,966
3,959 stars

1N3/IntruderPayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

Metrics details
Stars3,959
3,807 stars

antonio-morales/Fuzzing101

An step by step fuzzing tutorial. A GitHub Security Lab initiative

Metrics details
Stars3,807
3,719 stars

Astrosp/osint-tools

OSINT tools can be used for Information gathering, Cybersecurity, Reverse searching, bugbounty, trust and safety, red team oprations and more.

Metrics details
Stars3,719
3,607 stars

Az0x7/vulnerability-Checklist

This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter

Metrics details
Stars3,607
3,513 stars

vaib25vicky/awesome-mobile-security

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.

Metrics details
Stars3,513
3,460 stars

edoardottt/cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Metrics details
Stars3,460
3,366 stars

opsdisk/pagodo

pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching

Metrics details
Stars3,366
3,323 stars

codingo/NoSQLMap

Automated NoSQL database enumeration and web application exploitation tool.

Metrics details
Stars3,323
3,313 stars

gwen001/pentest-tools

A collection of custom security tools for quick needs.

Metrics details
Stars3,313
3,198 stars

six2dez/OneListForAll

Rockyou for web fuzzing

Metrics details
Stars3,198
3,164 stars

dwisiswant0/awesome-oneliner-bugbounty

A collection of awesome one-liner scripts especially for bug bounty tips.

Metrics details
Stars3,164
3,154 stars

sa7mon/S3Scanner

Scan for misconfigured S3 buckets across S3-compatible APIs!

Metrics details
Stars3,154
3,136 stars

devanshbatham/ParamSpider

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

Metrics details
Stars3,136
3,020 stars

projectdiscovery/uncover

Quickly discover exposed hosts on the internet using multiple search engines.

Metrics details
Stars3,020
2,985 stars

jaeles-project/gospider

Gospider - Fast web spider written in Go

Metrics details
Stars2,985
2,815 stars

Voorivex/pentest-guide

Penetration tests guide based on OWASP including test cases, resources and examples.

Metrics details
Stars2,815
2,768 stars

gh0stkey/Web-Fuzzing-Box

Web Fuzzing Box - Web 模糊测试字典与一些Payloads

Metrics details
Stars2,768
2,695 stars

Impact-I/reFlutter

Flutter Reverse Engineering Framework

Metrics details
Stars2,695
2,491 stars

caido/caido

🚀 Caido releases, wiki and roadmap

Metrics details
Stars2,491
2,414 stars

screetsec/Sudomy

Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting

Metrics details
Stars2,414
2,378 stars

terjanq/Tiny-XSS-Payloads

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

Metrics details
Stars2,378
2,375 stars

payloadbox/command-injection-payload-list

🎯 Command Injection Payload List

Metrics details
Stars2,375
2,365 stars

jaeles-project/jaeles

The Swiss Army knife for automated Web Application Testing

Metrics details
Stars2,365
2,323 stars

ssl/ezXSS

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

Metrics details
Stars2,323
2,317 stars

hisxo/gitGraber

gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...

Metrics details
Stars2,317
2,287 stars

1N3/BruteX

Automatically brute force all services running on a target.

Metrics details
Stars2,287
2,240 stars

inonshk/31-days-of-API-Security-Tips

This challenge is Inon Shkedy's 31 days API Security Tips.

Metrics details
Stars2,240
2,218 stars

d3mondev/puredns

Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.

Metrics details
Stars2,218
1-60 of 472 projects
Get A Weekly Email With Trending Bugbounty Projects
Stay updated on Bugbounty plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.