Bug Bounty Security Tools
Browse Cybersecurity Tools in this category
24 InfoSec Tools
knock
by guelfoweb
Knock Subdomain Scan
shosubgo
by incogbyte
Small tool to Grab subdomains using Shodan api.
cero
by glebarez
Scrape domain names from SSL certificates of arbitrary hosts
web_app_recon_ci-cd_public
by onurcangnc
This project delivers a fully automated **Recon-as-Code** workflow for passive reconnaissance for web application environments. It combines GitHub Actions-based CI/CD automation, powerful recon tools, and a Flask-powered dashboard for visualized and authenticated access to the findings.
S3BucketMisconf
by Atharv834
S3BucketMisconf is an advanced tool designed to scan AWS S3 buckets for misconfigurations. It identifies publicly accessible buckets, checks permissions, and detects sensitive data leaks. Ideal for bug bounty hunters and pentesters, it automates the recon process and enhances cloud storage security assessment efficiently.
csprecon
by edoardottt
Discover new target domains using Content Security Policy
favirecon
by edoardottt
Use favicons to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.
4-ZERO-3
by Dheerajmadhukar
403/401 Bypass Methods + Bash Automation + Your Support ;)
back-me-up
by Dheerajmadhukar
This tool will check for Sensitive Data Leakage with some useful patterns/RegEx. The patterns are mostly targeted on waybackdata and filter everything accordingly.
recox
by samhaxr
Master script for web reconnaissance
socialhunter
by utkusen
crawls the website and finds broken social media links that can be hijacked
hades
by joelindra
Automate your hacking
jxscout
by francisconeves97
jxscout superpowers JavaScript analysis for security researchers
aem-hacker
by 0ang3el
An MCP server implementation
SubEnum
by bing0o
bash script for Subdomain Enumeration
uro
by s0md3v
declutters url lists for crawling/pentesting
SecretFinder
by m4ll0k
SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files
LinkFinder
by GerbenJavado
A python script that finds endpoints in JavaScript files
dnsx
by projectdiscovery
dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.
dnsgen
by AlephNullSK
DNSGen is a powerful and flexible DNS name permutation tool designed for security researchers and penetration testers. It generates intelligent domain name variations to assist in subdomain discovery and security assessments.
lazyrecon
by nahamsec
This script is intended to automate your reconnaissance process in an organized fashion
assetfinder
by tomnomnom
Find domains and subdomains related to a given domain
Sublist3r
by aboul3la
Fast subdomains enumeration tool for penetration testers
dalfox
by hahwul
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.