This is your work, valued

Porto alegre

KingOfTips

Elite
@KingOfBugbounty

Our main goal is to share tips from some well-known bughunters,We wish to influence Onelinetips and explain the commands, 4 the better understanding of hunter's

KingOfBugBountyTips. Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Onelinetips and explain the commands, for the better understanding of new hunters..

5.5k

enumrust. Subdomain Enumerator and Simple Crawler

451

Bugbounty-Checklist. Tips and Tutorials for Bug Bounty and also Penetration Tests.

124

s3tk. Go

89

KingRecon_DOD.

79

Bug-Bounty-Toolz. BBT - Bug Bounty Tools

65

DockerHunt. Shell

48

Discovery-Header-Bug-Bounty. Discovery Header Bug Bounty to DoD

47

Hardcoded-Token-Hunter. 🔐 Chrome Extension - Detect hardcoded tokens, API keys & secrets in JavaScript files

47

Dependency-Confusion-Hunter. 🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages

36

SecretFinder. SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

34

gitPullScrapper. Nuclei Pre-Master Template Downloader

22

crawlgoogle. Chrome extension to extract domains from Google search results - by ofjaaah

20

urlextract. URLess is a simple but powerful tool that removes paths from URLs, generating multiple variations of the base domain. This is useful for security testing, such as LFI (Local File Inclusion), path traversal, and directory fuzzing.

15

BugBuntu. BugBuntu Linux

15

caido-postman. Caido plugin for Postman integration - Search public collections, import API requests, replay through Caido, extract headers/body from APIs

11

nuclearpond-OFJAAAH. Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

10

hacks. A collection of hacks and one-off scripts

10

web-scraping. Anotações e scripts de web scraping, screen scraping, etc

10

shoscan-cli. Shodanscan is a bash scripting search queries using the shodan cli. 🔥

9

wordlists. Common Wordlists

9

airixss. Finding XSS during recon

8

uniqwordlist. Join wordlist file with subdomains, word by subdomain

7

axiom. The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!

6

SecLists. SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

6

nuclei-templates. Community curated list of templates for the nuclei engine to find security vulnerabilities.

6

bbrf-client. The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices

6

lemma. Python

6

jomlaGO. jomlaGO

6

OSINT-Brazuca. Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.

5

terraform-nuclear-pond-OFJAAAH. Backend for Nuclear Pond

5

assetfinder. Find domains and subdomains related to a given domain

4

samlists. Free, libre, effective, and data-driven wordlists for all!

4

rayder-workflows. Repo for hosting rayder workflows

4

freq. This is go CLI tool for send fast Multiple get HTTP request.

3

altdns. Generates permutations, alterations and mutations of subdomains and then resolves them

3

hackerone. 404

3

GitDorker. A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

3

gotator. Gotator is a tool to generate DNS wordlists through permutations.

2

haktldextract. Extract domains/subdomains from URLs en masse

2

HostileSubBruteforcer. Ruby

2

page-fetch. Fetch web pages using headless Chrome, storing all fetched resources including JavaScript files. Run arbitrary JavaScript on many web pages and see the returned values

2

faraday_plugins. Security tools report parsers for FaradaySEC

1

parrot-core. Files to include in the package parrot-core.

1