References
Reference · reference-indexdual-use

Awesome Bug Bounty Tools

A curated, security-specific directory of ~200+ open-source bug-bounty and pentest tools organized by phase and vulnerability class: reconnaissance (subdomain enum, port scanning, content discovery), exploitation (SQLi, XSS, XXE, SSRF, CSRF, command injection), and specialized scanning (JWT, S3 buckets, CMS, WAF evasion). CC0-licensed.

Use responsibly

Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.

Dual-use security content. We link to the upstream project rather than re-hosting ready-to-fire files. Use only in authorized security testing.

More references