Bug Bounty Security Tools

Browse Cybersecurity Tools in this category

24 InfoSec Tools

Gxss

Gxss

by KathanP19

A tool to check a bunch of URLs that contain reflecting params.

bugbounty bugbounty-tool golang
May 26, 2025
Gopherus

Gopherus

by tarunkant

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

fastcgi github-rce gopher
May 26, 2025
hakrawler

hakrawler

by hakluke

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

bugbounty crawling hacking
May 26, 2025
Jeeves

Jeeves

by ferreiraklet

Jeeves SQLI Finder

security tool
May 26, 2025
gitleaks

gitleaks

by gitleaks

Find secrets with Gitleaks 🔑

ai-powered ci-cd cicd
May 25, 2025
GraphQLmap

GraphQLmap

by swisskyrepo

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

capture-the-flag ctf fuzz
May 25, 2025
katana

katana

by projectdiscovery

A next-generation crawling and spidering framework.

cli crawler gocrawler
May 25, 2025
XSRFProbe

XSRFProbe

by 0xInfection

The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.

audit crafted-tokens crawler
May 25, 2025
Injectus

Injectus

by dubs3c

CRLF and open redirect fuzzer

crlf-injection open-redirect-injection python
May 25, 2025
Corsy

Corsy

by s0md3v

CORS Misconfiguration Scanner

cors cors-misconfiguration-scanner cors-scanner
May 25, 2025
reconftw

reconftw

by six2dez

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

bug-bounty bugbounty dns
May 25, 2025
subfinder

subfinder

by projectdiscovery

Fast passive subdomain enumeration tool.

bugbounty hacking osint
May 25, 2025
GitDorker

GitDorker

by obheda12

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

security tool
May 25, 2025
S3Scanner

S3Scanner

by sa7mon

Scan for misconfigured S3 buckets across S3-compatible APIs!

aws bugbounty gcp
May 25, 2025
fav-up

fav-up

by pielco11

IP lookup by favicon using Shodan

cloudflare cloudflare-bypass favicon-icon
May 25, 2025
crlfuzz

crlfuzz

by dwisiswant0

A fast tool to scan CRLF vulnerability written in Go

crlf-injection go golang
May 25, 2025
gauplus

gauplus

by bp0lr

Gau Plus

security tool
May 25, 2025
unimap

unimap

by Edu4rdSHL

Scan only once by IP address and reduce scan times with Nmap for large amounts of data.

ip-scan nmap open-ports
May 25, 2025
httpx

httpx

by projectdiscovery

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

bugbounty cli cybersecurity
May 25, 2025
dnsrecon

dnsrecon

by darkoperator

DNS Enumeration Script

security tool
May 25, 2025
nuclei

nuclei

by projectdiscovery

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

attack-surface cve-scanner dast
May 25, 2025
gospider

gospider

by jaeles-project

Gospider - Fast web spider written in Go

bugbounty crawler go
May 25, 2025
gotator

gotator

by Josue87

Gotator is a tool to generate DNS wordlists through permutations.

bug-bounty bugbounty reconnaissance
May 25, 2025
puredns

puredns

by d3mondev

Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.

bugbounty dns dns-bruteforcer
May 25, 2025