Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Bugbounty

Bugbounty

16 projects

Showing 16 of 16 projects

SubFinder
SubFinderGo

A fast, passive subdomain enumeration tool for security researchers and penetration testers.

#hacktoberfest#passive-scanning#osint
Stars14.1k
Forks1.6k
Last commit2 days ago
Awesome bug bounty resources by EdOverflow
Awesome bug bounty resources by EdOverflow

A community-curated collection of payloads, tools, and techniques for bug bounty hunters and security researchers.

#web-security#vulnerability-testing#infosec
Stars6.5k
Forks1.6k
Last commit2 years ago
APKLeaks
APKLeaksPython

A tool to scan APK files for URIs, endpoints, secrets, and sensitive data patterns.

#mobile-security#regex-patterns#apk-analysis
Stars6.2k
Forks583
Last commit11 months ago
Commix
CommixPython

An automated penetration testing tool that detects and exploits command injection vulnerabilities in web applications.

#open-source#owasp#web-security
Stars5.8k
Forks939
Last commit6 days ago
Fuzzing-101
Fuzzing-101

An step by step fuzzing tutorial. A GitHub Security Lab initiative

#fuzzer#fuzzilli#fuzzing
Stars3.8k
Forks420
Last commit1 month ago
InQL Scanner
InQL ScannerKotlin

A Burp Suite extension for advanced GraphQL security testing, featuring vulnerability scanning, batch attacks, and schema analysis.

#burpsuite#graphql#penetration-testing
Stars1.8k
Forks188
Last commit1 month ago
Android Reports and Resources
Android Reports and Resources

A curated collection of disclosed Android security reports from HackerOne and educational resources for vulnerability research.

#exploit-development#mobile-pentesting#android-resource
Stars1.7k
Forks329
Last commit10 months ago
AWSBucketDump
AWSBucketDumpPython

A security tool that enumerates AWS S3 buckets to discover and download interesting files using wordlist-based scanning.

#aws-security#python-tool#enumeration
Stars1.5k
Forks245
Last commit2 years ago
reFlutter
reFlutterPython

A reverse engineering framework for Flutter apps, enabling traffic interception and dynamic analysis via patched Flutter engines.

#dart#mobile-security#ios
Stars1.5k
Forks187
Last commit4 years ago
Redcloud
RedcloudPython

Automated deployment of red team infrastructure using Docker with a web interface for managing offensive security tools.

#portainer#red-team-infrastructure#pentest
Stars1.3k
Forks205
Last commit3 years ago
StaCoAn
StaCoAnJavaScript

A cross-platform static code analysis tool for mobile applications (APK/IPA) to find security vulnerabilities like hardcoded credentials and API keys.

#ipa-analysis#mobile-security#apk-analysis
Stars871
Forks139
Last commit5 years ago
CI/CD Attacks
CI/CD Attacks

A curated collection of offensive security research, techniques, and tools for attacking CI/CD pipelines and software supply chains.

#cicd#attack-techniques#red-teaming
Stars613
Forks58
Last commit1 month ago
bXSS
bXSSJavaScript

A utility for bug hunters and organizations to identify Blind Cross-Site Scripting vulnerabilities via customizable payloads and notifications.

#web-security#xss#cross-site-scripting
Stars577
Forks64
Last commit3 years ago
Gato-X
Gato-XPython

A fast scanning and attack toolkit for identifying and exploiting GitHub Actions vulnerabilities at scale.

#python-tool#cicd#red-teaming
Stars563
Forks52
Last commit4 days ago
Escape Graphinder - GraphQL Subdomain Enumeration
Escape Graphinder - GraphQL Subdomain EnumerationPython

A tool that extracts all GraphQL endpoints from a given domain using subdomain enumeration, script analysis, and brute force.

#spider#osint#subdomain-enumeration
Stars228
Forks14
Last commit3 years ago
ActionsTOCTOU (Time Of Check to Time Of Use)
ActionsTOCTOU (Time Of Check to Time Of Use)Python

A proof-of-concept tool demonstrating and exploiting TOCTOU vulnerabilities in GitHub Actions approval workflows.

#toctou#actions#cicd
Stars44
Forks7
Last commit6 months ago

Related Tags

#Penetration Testing8#Security Tool7#Bug Bounty7#Security5#Hacking5#Python5#Docker4#Mobile Security3#Web Security3#Devsecops3#Vulnerability Scanning3#Security Tools3
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub