web
3 resources across 3 kinds
Tools
- Open ↗Hettyactive
An open-source HTTP toolkit for security research and bug bounty positioned as a Burp Suite alternative. Provides a machine-in-the-middle HTTP proxy with request logging and advanced search, request interception/manipulation, an HTTP client for crafting and replaying requests, scope management, and project-based storage, all driven through a web-based admin interface.
Frameworks & agents
- Open ↗pentest-agentsactivedual-usehigh-risk
An autonomous bug-bounty framework that orchestrates AI coding assistants (Claude Code, Codex, Gemini, Cursor, etc.) across ~50 specialized agents by vulnerability class (XSS, SQLi, CSRF, SSRF, OAuth), with a 7-Question Gate validation pipeline, bug-bounty platform integrations, payload libraries, and scope/never-submit controls.
References
- Open ↗Bug Bounty Referencedual-use
A curated index of publicly disclosed bug bounty write-ups organized by vulnerability type (XSS, SQLi, CSRF, RCE, SSRF, auth bypass, etc.), linking out to the original researcher reports.