GitHub repo leaderboard by stars, growth rate and activity.
All about bug bounty (bypasses, payloads, and etc)
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
Asset inventory of over 800 public bug bounty programs.
BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.
API Security Project aims to present unique attack & defense methods in API Security field
🔱 Powerfull XSS Scanning and Parameter analysis tool&gem
These are my checklists which I use during my hunting.
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | All about bug bounty (bypasses, payloads, and etc) | — | 6,852 | last pushed 3 years ago | |
| 2 | Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。 | Shell | 2,073 | last pushed 3 years ago | |
| 3 | OSINT power without API key hassle | Go | 1,803 | last pushed 5 weeks ago | |
| 4 | Asset inventory of over 800 public bug bounty programs. | Shell | 1,606 | last pushed 2 years ago | |
| 5 | BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation. | C# | 1,567 | last pushed 6 years ago | |
| 6 | API Security Project aims to present unique attack & defense methods in API Security field | — | 1,448 | last pushed 3 years ago | |
| 7 | 🔱 Powerfull XSS Scanning and Parameter analysis tool&gem | Ruby | 1,363 | last pushed 6 months ago | |
| 8 | These are my checklists which I use during my hunting. | HTML | 894 | last pushed 1 week ago | |
| 9 | An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically. | Shell | 811 | last pushed 4 months ago |
All · 11,474