#bug-bounty (30 Repositories)
Ranked open-source repositories tagged with #bug-bounty, scored by pull request acceptance likelihood and maintainer engagement velocity.
15.3%
33.4h
30 repositories tagged #bug-bounty
xalgorix/xalgorix
Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
maurosoria/dirsearch
Web path scanner
elementalsouls/Claude-BugHunter
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
Kritt-ai/open-kritt
Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.
shuvonsec/claude-bug-bounty
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Scottcjn/rustchain-bounties
Earn RTC crypto by contributing to the RustChain ecosystem. Bounties from 1-150 RTC. Star, code, write tutorials, find bugs.
usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
reconmap/reconmap
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
tigerbeetle/viewstamped-replication-made-famous
A $20k consensus challenge based on TigerBeetle's implementation of the pioneering Viewstamped Replication protocol.
rix4uni/cvemapping
This repo Gathers all available cve exploits from github.⚠️ Be careful Malware.
edoardottt/secfiles
My useful files for penetration tests, security assessments, bug bounty and other security related stuff
rix4uni/medium-writeups
This repository updates latest Bug Bounty medium writeups every 10 minutes, https://readmedium.com/Medium_URL, https://archive.ph/Medium_URL, https://freedium.cfd/Medium_URL
matty69v/Bug-Bounty-Agents
AI-Powered Agents for Bub-Bounty Pentesting and Red-Teaming purposes
aydinnyunus/exifLooter
ExifLooter finds geolocation on all image urls and directories also integrates with OpenStreetMap
Chocapikk/wpprobe
A fast WordPress plugin enumeration tool
eslam3kl/SQLiDetector
Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.
0xSHAK1B/TIKTOK-SSL-Pinning-Bypass
Bypass TikTok SSL/TLS certificate pinning on Android to intercept & analyze HTTPS traffic — root & no-root, works with Burp Suite, mitmproxy & Reqable (2026).
Autumn-27/ScopeSentry
ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes
silentchainai/SILENTCHAIN
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
cdxiaodong/cain-agent
Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK
faiyazahmad07/xss_vibes
A modern tool written in Python that automates your xss findings.
CommonHuman-Lab/nyxstrike
AI Powered penetration testing Platform for offensive security research
0xSteph/pentest-ai-agents
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
Armur-Ai/Pentest-Swarm-AI
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go, Claude API, and 7+ native security tools.
aw-junaid/bug-bounty
Documenting my security research journey: This repository contains detailed vulnerability write-ups, proof-of-concept (PoC) exploits, and the custom automation tools I use for reconnaissance and system assessment.
x1337loser/Dependency-Confusion
All About Dependency Confusion Attack, (Detecting, Finding, Mitigating)
Zyrexnn/Cybermes
Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
ivan-sincek/android-penetration-testing-cheat-sheet
Work in progress...
adshao/flounder
Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.
edoardottt/missing-cve-nuclei-templates
Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and vulnerability assessments too.