Bug Bounty Security Tools
Browse Cybersecurity Tools in this category
24 InfoSec Tools
jxscout
by francisconeves97
jxscout superpowers JavaScript analysis for security researchers
aem-hacker
by 0ang3el
An MCP server implementation
SubEnum
by bing0o
bash script for Subdomain Enumeration
uro
by s0md3v
declutters url lists for crawling/pentesting
SecretFinder
by m4ll0k
SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files
LinkFinder
by GerbenJavado
A python script that finds endpoints in JavaScript files
dnsx
by projectdiscovery
dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.
dnsgen
by AlephNullSK
DNSGen is a powerful and flexible DNS name permutation tool designed for security researchers and penetration testers. It generates intelligent domain name variations to assist in subdomain discovery and security assessments.
lazyrecon
by nahamsec
This script is intended to automate your reconnaissance process in an organized fashion
assetfinder
by tomnomnom
Find domains and subdomains related to a given domain
Sublist3r
by aboul3la
Fast subdomains enumeration tool for penetration testers
dalfox
by hahwul
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Gxss
by KathanP19
A tool to check a bunch of URLs that contain reflecting params.
Gopherus
by tarunkant
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
hakrawler
by hakluke
Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application
Jeeves
by ferreiraklet
Jeeves SQLI Finder
gitleaks
by gitleaks
Find secrets with Gitleaks 🔑
GraphQLmap
by swisskyrepo
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
katana
by projectdiscovery
A next-generation crawling and spidering framework.
XSRFProbe
by 0xInfection
The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.
Injectus
by dubs3c
CRLF and open redirect fuzzer
Corsy
by s0md3v
CORS Misconfiguration Scanner
reconftw
by six2dez
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
subfinder
by projectdiscovery
Fast passive subdomain enumeration tool.