Bug Bounty Tools

Nmap

Network scanner for security auditing and network discovery.

httpx

Fast and multi-purpose HTTP toolkit for probing and reconnaissance.

Amass

In-depth attack surface mapping and asset discovery.

Subfinder

Fast subdomain enumeration tool using passive online sources.

Naabu

Fast port scanner for reconnaissance and attack surface mapping.

dnsx

DNS toolkit for advanced DNS queries and enumeration.

Nuclei

Fast vulnerability scanner for web applications with customizable templates.

Dalfox

Powerful XSS scanner and payload generator for web applications.

sqlmap

Automated tool for detecting and exploiting SQL injection flaws.

ffuf

Fast web fuzzer for content discovery and brute-forcing directories/files.

Photon

Crawler for automating OSINT and gathering URLs, files, and secrets.

dirsearch

Simple and fast command-line tool for brute-forcing web directories and files.

feroxbuster

Fast, simple, recursive content discovery tool for web applications.

MassDNS

High-performance DNS resolver for bulk DNS lookups and subdomain enumeration.

Findomain

Fastest and cross-platform subdomain enumerator.

OWASP ZAP

Integrated penetration testing tool for finding vulnerabilities in web apps.

Burp Suite

Popular web vulnerability scanner and proxy for manual and automated testing.

Shuffledns

Mass DNS resolver for subdomain enumeration using multiple resolvers.

SpiderFoot

Automated OSINT tool for threat intelligence and asset discovery.

theHarvester

Email, domain, and username enumeration from public sources.

Sublist3r

Fast subdomain enumeration using OSINT techniques.

Holehe

Check if an email is used on online services for OSINT investigations.

Aquatone

Domain flyover tool for visual inspection of targets.

Pacu

Powerful AWS exploitation framework for security testing and automation.

Prowler

Security tool to perform AWS security best practices assessments.

AWS Recon

Cloud reconnaissance tool for AWS environments.

PowerUpSQL

SQL Server security auditing and attack automation toolkit for cloud and on-prem.

GitLeaks

Scan git repos for secrets and credentials, useful for cloud asset discovery.

GCP Scanner

Security scanner for Google Cloud Platform resources and misconfigurations.

OWASP MSTG

Mobile Security Testing Guide with checklists and test cases for Android/iOS.

AppMon

Automated framework for monitoring and tampering Android/iOS apps.

Androguard

Reverse engineering and analysis toolkit for Android applications.

Frida

Dynamic instrumentation toolkit for developers, reverse engineers, and security researchers.

Objection

Runtime mobile exploration toolkit powered by Frida for Android/iOS.

Commix

Automated tool for finding and exploiting command injection vulnerabilities in APIs.

Arjun

HTTP parameter discovery suite.

AScan

Lightweight API security scanner for REST APIs.

API Security Checklist

Comprehensive checklist for testing API endpoints for vulnerabilities.

APIScanner

Automated API vulnerability scanner for REST APIs.

Turbo Intruder

Fast HTTP request generator for advanced API and web fuzzing.

OWASP crAPI

Completely ridiculous API for learning and practicing API security testing.

ApiFuzz

Automated API fuzzing tool for bug bounty and pentesting.

ParamSpider

Find URL parameters for a given domain to help with bug hunting.

crtndstry

Extract subdomains from Certificate Transparency logs for reconnaissance.

Can I Take Over XYZ?

List of services vulnerable to subdomain takeover.

CloudScraper

Tool for scraping and enumerating cloud assets and endpoints.

hunt-s3

Find publicly accessible AWS S3 buckets for bug bounty hunting.

hunt-dns

Automated DNS reconnaissance tool for bug bounty hunters.

hunt-subdomains

Find subdomains using multiple sources for better coverage.

Sublist3r

Fast subdomains enumeration tool for penetration testers.

Amass

In-depth Attack Surface Mapping and Asset Discovery.

massdns

High-performance DNS stub resolver for bulk lookups and reconnaissance.

Findomain

The fastest and cross-platform subdomain enumerator.

Sudomy

Automated subdomain enumeration and domain analysis for bug hunting.

chaos-client

Go client to communicate with Chaos DNS API.

domained

Multi Tool Subdomain Enumeration.

bugcrowd-levelup-subdomain-enumeration

Esoteric sub-domain enumeration techniques from Bugcrowd LevelUp 2017.

shuffledns

Wrapper around massdns for active bruteforce and wildcard handling.

puredns

Fast domain resolver and subdomain bruteforcing with wildcard filtering.

censys-subdomain-finder

Subdomain enumeration using certificate transparency logs from Censys.

Turbolist3r

Subdomain enumeration tool with analysis features for discovered domains.

censys-enumeration

Extract subdomains/emails for a domain using Censys SSL/TLS dataset.

tugarecon

Fast subdomains enumeration tool for penetration testers.

as3nt

Another Subdomain ENumeration Tool.

Subra

Web-UI for subdomain enumeration (subfinder).

Substr3am

Passive reconnaissance/enumeration by watching for SSL certificates.

enumall.py

Setup script for Regon-ng.

altdns

Generates permutations, alterations and mutations of subdomains.

brutesubs

Automation framework for running multiple subdomain bruteforcing tools.

dns-parallel-prober

Parallelised domain name prober for fast subdomain discovery.

dnscan

Python wordlist-based DNS subdomain scanner.

knock

Knockpy: Python tool for enumerating subdomains through a wordlist.

hakrevdns

Small, fast tool for performing reverse DNS lookups en masse.

dnsx

Fast and multi-purpose DNS toolkit for multiple DNS queries.

subfinder

Subdomain discovery tool for valid subdomains.

assetfinder

Find domains and subdomains related to a given domain.

crtndstry

Yet another subdomain finder using certificate transparency logs.

VHostScan

Virtual host scanner that performs reverse lookups.

scilla

Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration.

sub3suite

Suite of tools for subdomain enumeration and attack surface mapping.

cero

Scrape domain names from SSL certificates of arbitrary hosts.

shosubgo

Grab subdomains using Shodan API.

haktrails

Golang client for querying SecurityTrails API data.

bbot

Recursive internet scanner for hackers.

parameth

Brute discover GET and POST parameters.

param-miner

Extension to identify hidden, unlinked parameters.

ParamPamPam

Brute discover GET and POST parameters.

Arjun

HTTP parameter discovery suite.

ParamSpider

Mining parameters from dark corners of Web Archives.

x8

Hidden parameters discovery suite written in Rust.

LinkFinder

Python script that finds endpoints in JavaScript files.

JS-Scan

PHP .js scanner designed to scrape URLs and other info.

LinksDumper

Extract links/possible endpoints from responses & filter them via decoding/sorting.

GoLinkFinder

Fast and minimal JS endpoint extractor.

BurpJSLinkFinder

Burp Extension for passive scanning JS files for endpoint links.

urlgrab

Golang utility to spider through a website searching for additional links.

waybackurls

Fetch all the URLs that the Wayback Machine knows about for a domain.

gau

Fetch known URLs from AlienVault's OTX, Wayback Machine, and Common Crawl.

getJS

Tool to fastly get all javascript sources/files.

linx

Reveals invisible links within JavaScript files.

waymore

Find way more from the Wayback Machine!

xnLinkFinder

Discover endpoints, potential parameters, and a target specific wordlist for a given target.

wfuzz

Web application fuzzer.

ffuf

Fast web fuzzer written in Go.

fuzzdb

Dictionary of attack patterns and primitives for black-box application fault injection.

IntruderPayloads

Collection of Burpsuite Intruder payloads, fuzz lists, and web pentesting methodologies.

fuzz.txt

Potentially dangerous files for fuzzing.

fuzzilli

JavaScript Engine Fuzzer.

fuzzapi

Tool for REST API pentesting using API_Fuzzer gem.

qsfuzz

Build your own rules to fuzz query strings and identify vulnerabilities.

vaf

Very advanced (web) fuzzer written in Nim.

Burp Suite Extension Store

Official Burp Suite extension marketplace for web security testing.

HackBar

Popular Chrome extension for manual web penetration testing and payload encoding.

Retire.js Extension

Detects vulnerable JavaScript libraries in web pages.

FoxyProxy

Proxy management extension for switching between proxies easily.

Bug Bounty Toolkit

Unpopular but useful extension for bug bounty hunters (quick links, payloads, tools).

CTF Tools

Unpopular extension with CTF and bug bounty utilities (hashing, encoding, decoding).

HTTP Headers

View HTTP response headers for any web page.

Wappalyzer Extension

Detects technologies used on websites (CMS, frameworks, analytics, etc).

XSS Radar

Unpopular extension for detecting reflected XSS vulnerabilities in web pages.

Cookie Editor

Edit, delete, and create cookies for bug bounty and pentesting.

Link Gopher

Extracts all links from web page, sorts them, removes duplicates, and displays them in a new tab for inspection or copy and paste into other systems.

Find Broken Links

Checks web pages for broken links and displays the results.

DotGit

GitHub repository discovery tool for bug bounty hunters to check if .git is exposed in visited websites.

OpenList

Open all links from a list in new tabs.

Open Multiple URLs

Open multiple URLs at once in new tabs.

Retire.js

Detects the use of JavaScript libraries with known vulnerabilities.

TruffleHog

Searches through git repositories for high entropy strings and secrets.

OneTab

Consolidates all your open tabs into a single tab for easier management.