Lists (9)
Sort Name ascending (A-Z)
Stars
A curated list of MCP servers for bug bounty.
🤖 LLM-powered agent for automated Google Dorking in bug hunting & pentesting.
Burp Plugin to Bypass WAFs through the insertion of Junk Data
Scira (Formerly MiniPerplx) is a minimalistic AI-powered search engine that helps you find information on the internet and cites it too. Powered by Vercel AI SDK! Open Source perplexity alternative.
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
GO Simple Tunnel - a simple tunnel written in golang
A suite of secret scanners built in Rust for performance. Based on TruffleHog (https://github.com/dxa4481/truffleHog) which is written in Python.
An enterprise friendly way of detecting and preventing secrets in code.
Abuse trust-boundaries to bypass firewalls and network controls
Lightweight anonymous browser that works via I2P. Ideal for those who want quick and easy access to I2P without heavy add-ons.
This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
Firepwn is a tool made for testing the Security Rules of a firebase application.
403/401 Bypass Methods + Bash Automation + Your Support ;)
Bypass-Four03 is a powerful bash tool designed to help testers bypass HTTP 403 forbidden errors through various path and header manipulation techniques. It also includes fuzzing for HTTP methods an…
A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
The code base behind the [Former] UnsecuredAPIKeys.com
A tutorial website for plain vanilla web development
This challenge is Inon Shkedy's 31 days API Security Tips.
🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.
Perplexica is an AI-powered search engine. It is an Open source alternative to Perplexity AI
Find S3 AWS/GCP/Azure buckets while surfing. S3DNS acts as DNS server, follows CNAMEs and matches any bucket pattern
Cybersecurity AI (CAI), the framework for AI Security
A complete, beginner-friendly bug bounty roadmap that takes you from zero experience to earning your first bounty.
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.