Skip to content
View codehunt2's full-sized avatar

Block or report codehunt2

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Python 1,837 235 Updated May 20, 2024

An HTTP toolkit for security research.

Go 9,003 492 Updated Feb 5, 2025

Remove duplicates from MASSIVE wordlist, without sorting it (for dictionary-based password cracking)

C++ 960 98 Updated Nov 4, 2025

This repo contain scripts written for finding subdomains using various available tools

Shell 26 10 Updated Oct 21, 2020

Mobile application testing toolkit

Python 242 54 Updated Nov 8, 2018

Bug Bounty Roadmaps

1,706 297 Updated Jun 12, 2021

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

HTML 314 80 Updated Jun 1, 2022

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

JavaScript 10,524 2,932 Updated Nov 16, 2025

Top disclosed reports from HackerOne

Python 5,014 909 Updated Nov 9, 2025

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Go 4,773 875 Updated Jan 23, 2025

Collection of methodology and test case for various web vulnerabilities.

6,827 1,866 Updated Jun 25, 2025

A tool to find subdomains or domains from passive sources.

Rust 113 15 Updated Jan 20, 2021

Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.

Dockerfile 764 154 Updated Mar 11, 2022

Docker image that provides features similar to Burp Collaborator

Dockerfile 15 4 Updated Mar 6, 2021

Automation for javascript recon in bug bounty.

Shell 1,057 185 Updated Sep 9, 2023

My CodeQL repository.

CodeQL 3 Updated Aug 14, 2020

take a list of old subdomain and new subdomain and the output is the deleted subdomain and the new subdomain

Shell 9 4 Updated Jun 28, 2020

BBT - Bug Bounty Tools (examples💡)

Python 1,855 476 Updated Apr 5, 2024

Lesser Known Web Attack Lab

CSS 331 47 Updated Feb 7, 2020

A Workflow Engine for Offensive Security

Go 5,955 949 Updated Aug 8, 2025

RECON Notes taking from every fucking book about bugbounty and web-app penetration testing exists

20 6 Updated Feb 29, 2020

Secret and/or credential patterns used for gf.

Shell 242 51 Updated Feb 10, 2023

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

Go 4,669 501 Updated Jan 1, 2025

A one liner Bash command which finds CORS in every possible endpoint.

148 44 Updated Jan 1, 2021

A Payload Injector for bugbounties written in go

Go 70 26 Updated Jul 18, 2020

Awesome list dedicated to Windows Subsystem for Linux

6,132 299 Updated Jun 27, 2024

Cross-site scripting labs for web application security enthusiasts

PHP 321 48 Updated Jun 2, 2021

A collection of all the data i could extract from 1 billion leaked credentials from internet.

3,199 415 Updated Jul 1, 2020

Bug Bounty stuffs, payloads, scripts, profiles, tips and tricks, ...

BitBake 147 32 Updated Jul 30, 2020
Next