Bug Bounty Security Tools

Browse Cybersecurity Tools in this category

24 InfoSec Tools

jxscout

jxscout

by francisconeves97

jxscout superpowers JavaScript analysis for security researchers

security tool
May 28, 2025
aem-hacker

aem-hacker

by 0ang3el

An MCP server implementation

security tool
May 27, 2025
SubEnum

SubEnum

by bing0o

bash script for Subdomain Enumeration

security tool
May 27, 2025
uro

uro

by s0md3v

declutters url lists for crawling/pentesting

security tool
May 26, 2025
SecretFinder

SecretFinder

by m4ll0k

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

security tool
May 26, 2025
LinkFinder

LinkFinder

by GerbenJavado

A python script that finds endpoints in JavaScript files

endpoints infosec
May 26, 2025
dnsx

dnsx

by projectdiscovery

dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.

cli dns-bruteforcer dns-client
May 26, 2025
dnsgen

dnsgen

by AlephNullSK

DNSGen is a powerful and flexible DNS name permutation tool designed for security researchers and penetration testers. It generates intelligent domain name variations to assist in subdomain discovery and security assessments.

domains osint recon
May 26, 2025
lazyrecon

lazyrecon

by nahamsec

This script is intended to automate your reconnaissance process in an organized fashion

security tool
May 26, 2025
assetfinder

assetfinder

by tomnomnom

Find domains and subdomains related to a given domain

security tool
May 26, 2025
Sublist3r

Sublist3r

by aboul3la

Fast subdomains enumeration tool for penetration testers

security tool
May 26, 2025
dalfox

dalfox

by hahwul

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

bugbounty bugbounty-tool cicd-pipeline
May 26, 2025
Gxss

Gxss

by KathanP19

A tool to check a bunch of URLs that contain reflecting params.

bugbounty bugbounty-tool golang
May 26, 2025
Gopherus

Gopherus

by tarunkant

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

fastcgi github-rce gopher
May 26, 2025
hakrawler

hakrawler

by hakluke

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

bugbounty crawling hacking
May 26, 2025
Jeeves

Jeeves

by ferreiraklet

Jeeves SQLI Finder

security tool
May 26, 2025
gitleaks

gitleaks

by gitleaks

Find secrets with Gitleaks 🔑

ai-powered ci-cd cicd
May 25, 2025
GraphQLmap

GraphQLmap

by swisskyrepo

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

capture-the-flag ctf fuzz
May 25, 2025
katana

katana

by projectdiscovery

A next-generation crawling and spidering framework.

cli crawler gocrawler
May 25, 2025
XSRFProbe

XSRFProbe

by 0xInfection

The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.

audit crafted-tokens crawler
May 25, 2025
Injectus

Injectus

by dubs3c

CRLF and open redirect fuzzer

crlf-injection open-redirect-injection python
May 25, 2025
Corsy

Corsy

by s0md3v

CORS Misconfiguration Scanner

cors cors-misconfiguration-scanner cors-scanner
May 25, 2025
reconftw

reconftw

by six2dez

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

bug-bounty bugbounty dns
May 25, 2025
subfinder

subfinder

by projectdiscovery

Fast passive subdomain enumeration tool.

bugbounty hacking osint
May 25, 2025