Bug Bounty Security Tools
Browse Cybersecurity Tools in this category
24 InfoSec Tools
Gxss
by KathanP19
A tool to check a bunch of URLs that contain reflecting params.
Gopherus
by tarunkant
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
hakrawler
by hakluke
Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application
Jeeves
by ferreiraklet
Jeeves SQLI Finder
gitleaks
by gitleaks
Find secrets with Gitleaks 🔑
GraphQLmap
by swisskyrepo
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
katana
by projectdiscovery
A next-generation crawling and spidering framework.
XSRFProbe
by 0xInfection
The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.
Injectus
by dubs3c
CRLF and open redirect fuzzer
Corsy
by s0md3v
CORS Misconfiguration Scanner
reconftw
by six2dez
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
subfinder
by projectdiscovery
Fast passive subdomain enumeration tool.
GitDorker
by obheda12
A Python program to scrape secrets from GitHub through usage of a large repository of dorks.
S3Scanner
by sa7mon
Scan for misconfigured S3 buckets across S3-compatible APIs!
fav-up
by pielco11
IP lookup by favicon using Shodan
crlfuzz
by dwisiswant0
A fast tool to scan CRLF vulnerability written in Go
gauplus
by bp0lr
Gau Plus
unimap
by Edu4rdSHL
Scan only once by IP address and reduce scan times with Nmap for large amounts of data.
httpx
by projectdiscovery
httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
dnsrecon
by darkoperator
DNS Enumeration Script
nuclei
by projectdiscovery
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
gospider
by jaeles-project
Gospider - Fast web spider written in Go
gotator
by Josue87
Gotator is a tool to generate DNS wordlists through permutations.
puredns
by d3mondev
Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.