Tool · reconpassiveopt-in
h1stats
A Python3 scraper that pulls data from HackerOne's GraphQL API to compile bug-bounty program statistics into a sortable CSV, extracting 23+ data points per program (bounty ranges, response/resolution times, total payouts, report volume, program age). Scrapes public programs by default and supports authenticated access to private programs via session cookie, aiding target selection.
More tools
- AmassreconDeep passive subdomain enumeration across many public sources.
- assetfinderreconFast passive subdomain discovery drawing on crt.sh, certspotter, hackertarget, threatcrowd and wayback.
- cdncheckreconClassifies a host as CDN, WAF or cloud and names the provider.
- dnsxreconFast DNS resolution and record enumeration from ProjectDiscovery.
- Fast Google Dorks ScanreconAn automated bash tool that runs a large set of Google dork search queries against a target domain to surface admin panels, widely-exposed file types and locations, and potential path-traversal exposures. Runs directly on Linux/Kali or via Docker, takes only a domain name as input, and supports an optional request proxy.
- github-searchreconCollection of Bash/Python/PHP scripts for reconnaissance against GitHub: credential/secret discovery, user and employee enumeration, dorking, subdomain enumeration, and repository/endpoint extraction. Authored by bug-bounty researcher gwen001.