bug-bounty
20 resources across 4 kinds
Tools
- Open ↗h1statspassiveopt-in
A Python3 scraper that pulls data from HackerOne's GraphQL API to compile bug-bounty program statistics into a sortable CSV, extracting 23+ data points per program (bounty ranges, response/resolution times, total payouts, report volume, program age). Scrapes public programs by default and supports authenticated access to private programs via session cookie, aiding target selection.
- Open ↗Hettyactive
An open-source HTTP toolkit for security research and bug bounty positioned as a Burp Suite alternative. Provides a machine-in-the-middle HTTP proxy with request logging and advanced search, request interception/manipulation, an HTTP client for crafting and replaying requests, scope management, and project-based storage, all driven through a web-based admin interface.
- Open ↗github-searchactivedual-use
Collection of Bash/Python/PHP scripts for reconnaissance against GitHub: credential/secret discovery, user and employee enumeration, dorking, subdomain enumeration, and repository/endpoint extraction. Authored by bug-bounty researcher gwen001.
- Open ↗keyhacks.shactivedual-use
Bash tool that checks the validity of leaked API keys and tokens across 50+ services (AWS, Azure, GCP, Slack, Stripe, GitHub, etc.) by issuing test requests. Useful for triaging secrets found during authorized assessments.
- Open ↗Phoenix Scopepassive
A microservice application that aggregates bug bounty program scope data across HackerOne, Bugcrowd, Intigriti and YesWeHack, exposing APIs and dashboards with scope-change alerts and asset enumeration to help researchers track in-scope targets.
Frameworks & agents
- Open ↗pentest-agentsactivedual-usehigh-risk
An autonomous bug-bounty framework that orchestrates AI coding assistants (Claude Code, Codex, Gemini, Cursor, etc.) across ~50 specialized agents by vulnerability class (XSS, SQLi, CSRF, SSRF, OAuth), with a 7-Question Gate validation pipeline, bug-bounty platform integrations, payload libraries, and scope/never-submit controls.
- Open ↗Cybersecurity AI (CAI)activehigh-riskdual-use
An open-source framework for building AI-powered offensive and defensive security automation, using ReACT-model agents with tools for command execution, web recon and code analysis, plus handoffs, swarm/hierarchical patterns, guardrails and human-in-the-loop. Supports 300+ models across providers and targets bug bounty, vulnerability discovery and exploitation workflows.
- Open ↗Claude-BugHunteractivedual-use
A Claude Code skill bundle for authorized security testing, providing 83 skills, 15 slash commands and pattern databases with hunt templates for 58 web vulnerability classes (XSS, SQLi, SSRF, IDOR) plus recon/OSINT and reporting workflows. Includes authorization gates and excludes internal AD, C2 and post-exploitation.
- Open ↗BugHunteractivedual-usehigh-risk
An AI-powered bug bounty toolkit (standalone CLI and Claude Code plugin) that runs an autonomous scope-to-report loop: recon, hunting across 26+ web vulnerability classes and smart-contract bug categories, a validation gate, and submission-ready reports for HackerOne, Bugcrowd, Intigriti, and Immunefi. Orchestrates ~35 external scanners and supports Ollama/Groq or paid AI providers.
- Open ↗DorkAgentpassiveopt-in
An LLM-powered agent (built on CrewAI) that automates Google Dorking for reconnaissance in penetration testing and bug bounty. It generates and refines dork queries with an LLM (OpenAI, Anthropic, or Gemini), analyzes results, and produces structured vulnerability reports to surface information disclosure, misconfigurations, and exposed sensitive data.
- Open ↗InstaVM Security Skillsdual-uselicence
Agent skills for Claude Code, Gemini CLI or other Skills/MCP agents that analyze mitmproxy-captured traffic for vulnerability classes such as IDOR, SSRF, SQLi, auth and secrets, distilled from disclosed HackerOne bug bounty reports.
Benchmarks
- Open ↗
Bug-bounty evaluation of 40 historical bounties across 25 real systems with separate Detect, Exploit, and Patch tasks and executable graders.
References
- Open ↗Awesome Bug Bounty Builderdual-uselicence
A security-specific collection: a bash installer that deploys 40+ recon and exploitation tools (Amass, Sublist3r, SQLmap, Nikto, FFUF) plus curated usage examples and one-liners for testing XSS, SQLi, SSRF, LFI and auth-bypass. GPL-3.0.
- Open ↗Can I take over xyz?dual-use
A community-maintained catalog of services (80+) vulnerable to subdomain takeover, with per-service status, regex fingerprints for identifying vulnerable endpoints, and CI verification. Includes guidance for demonstrating takeovers responsibly.
- Open ↗
Structured cybersecurity learning roadmaps for several tracks (hobbyist, accelerated entry, bug-bounty hunter, certification, degree), pointing to platforms like TryHackMe, Hack The Box, and PortSwigger Academy and to CompTIA/OffSec certification paths.
- Open ↗Google Dorks for Bug Bountydual-usepassive
A categorized collection of 40+ Google search queries (dorks) for bug-bounty and pentest reconnaissance, targeting exposed config/log files, XSS/SQLi/SSRF/LFI-prone parameters, API endpoints, login/test environments, cloud storage misconfigurations, and leaked credentials. It also includes an interactive dork tool and links to related dork collections.
- Open ↗
A curated archive of publicly disclosed bug bounty reports in Markdown, each covering vulnerability type, impact, reproduction steps, remediation and links to the original disclosure. Organized under a /reports directory as an educational reference for security researchers and developers.
- Open ↗Bug Bounty Referencedual-use
A curated index of publicly disclosed bug bounty write-ups organized by vulnerability type (XSS, SQLi, CSRF, RCE, SSRF, auth bypass, etc.), linking out to the original researcher reports.
- Open ↗HackerOne Reportsdual-use
A repository that aggregates and ranks disclosed HackerOne bug bounty reports, categorizing them by vulnerability type (XSS, SQLi, RCE, SSRF, etc.) and by affected program, linking out to the original disclosures.
- Open ↗Awesome Bug Bounty Toolsdual-use
A curated, security-specific directory of ~200+ open-source bug-bounty and pentest tools organized by phase and vulnerability class: reconnaissance (subdomain enum, port scanning, content discovery), exploitation (SQLi, XSS, XXE, SSRF, CSRF, command injection), and specialized scanning (JWT, S3 buckets, CMS, WAF evasion). CC0-licensed.