03 Aug 2026
JavaScript
★ 37
The Solana Security Standard (SOL-0XX) is a tool that integrates security rules into development environments to detect Solana-specific vulnerabilities in real time, based on insights from $514M worth of exploits. It features a comprehensive set of 52 rules covering various bug classes, with support for multiple IDEs and CI tools, and allows for easy installation through plugins for different platforms. This tool emphasizes immediate feedback on potential security issues as developers write code for Solana programs.
03 Aug 2026
★ 12
Shodan Filters is a curated repository of search queries specifically designed for Shodan, facilitating reconnaissance and asset discovery during penetration testing and bug bounty engagements. It offers a comprehensive list of ready-to-use filters categorized by technology and framework, enabling users to efficiently discover vulnerable components and configurations by simply entering queries in the Shodan search bar. Notable features include a variety of targeted filters for different technologies, such as Ruby, Django, Kubernetes, and WordPress, which help streamline the information gathering process.
03 Aug 2026
Go
★ 13
S3Finder is a high-performance command-line interface tool designed for discovering AWS S3 buckets through intelligent name generation and high-concurrency scanning. It offers features such as decoupled input sources, an AI-powered permutation engine for bucket name variations, deep inspection with AWS SDK integration, and real-time progress tracking, all while maintaining adaptive rate limiting to avoid throttling and IP blocks. This tool supports cross-platform operation and allows for flexible output formats, making it suitable for security assessments and reconnaissance efforts.
03 Aug 2026
JavaScript
★ 48
ReconPro is a web reconnaissance tool catering to cybersecurity professionals and bug bounty hunters, facilitating the rapid identification of vulnerabilities through a curated library of Google dorks. It features a smart preset system for common scenarios, supports dual themes, and operates cross-platform without external dependencies, allowing users to easily execute targeted searches for specific vulnerabilities.
03 Aug 2026
Shell
★ 12
ReconOps is a structured, recon-only framework designed for bug bounty hunters, focusing on mapping and understanding the attack surface before exploitation. It provides a comprehensive methodology and tools for both passive and active reconnaissance, including automated scripts and templates for effective recon operations. Notable features include tiered guidance for various stages of reconnaissance, a checklist for engagements, and extensive documentation on techniques and tools.
03 Aug 2026
Shell
★ 12
ps.sh is a Bash script designed for automated port scanning on specified target hosts, enhancing scan efficiency and reducing time. It offers features such as service discovery through various workflows using Nmap and Masscan, as well as support for scanning multiple targets simultaneously. Notably, users can customize target ports and output directories, making it a versatile tool for network exploration.
03 Aug 2026
Python
★ 815
The Pentest Agent Suite is an autonomous bug-bounty framework designed for use with Claude Code and six other AI coding tools, featuring a collection of 50 agents, 26 commands, and 19 CLI tools. It provides a comprehensive methodology for vulnerability hunting, including automated exploit chaining, endpoint tracking, semantic writeup searches, and installation compatibility across multiple development environments. Its core functionalities enable users to efficiently conduct security assessments and manage bounties via integration with live platforms and cost tracking mechanisms.
03 Aug 2026
JavaScript
★ 35
PenScope is a comprehensive Chrome extension designed for bug bounty hunters, enabling automated map and probe functionalities within web applications. It autonomously scans an attack surface, identifies potential vulnerabilities, and generates HackerOne-format reports for critical findings, streamlining the workflow significantly. Notable features include enhanced probing capabilities with 45 attack vectors, extensive secret pattern recognition, and the ability to decode JWTs and log sensitive information without sending data until prompted by the user.
03 Aug 2026
Python
★ 29
The "penetration-testing-notes" repository serves as a comprehensive collection of notes on penetration testing and related technologies. Designed for educational purposes, it encompasses multiple resources from various platforms, providing insights and references to enhance penetration testing skills. Notable features include curated content from reputable sources like Hack The Box, PortSwigger Academy, and OWASP, aimed at facilitating learning and practical application in cybersecurity.
03 Aug 2026
Rust
★ 155
Pathbuster is a path-normalization penetration testing tool built with Rust, designed to aid ethical hackers in scanning for vulnerabilities in web applications. It features an array of options for configuring requests, including various HTTP methods, custom headers, response filtering, and even supports proxy configurations for integrated use with tools like Burp Suite. Notable enhancements include unified response filtering, customized brute-force control, ETA estimations, and traversal strategy selection, making it a versatile choice for web application assessments.
03 Aug 2026
Python
★ 12
OnlyVulns is a nonprofit, open-source platform designed for security researchers to publish vulnerability disclosures in a controlled and safe environment. It enables researchers to document their findings, including proof-of-concept submissions and technical write-ups, while allowing them to manage vendor communications and disclosure timelines autonomously. Key features include a non-corporate framework, an embargo process for pre-publication coordination, and options for community support and tipping, fostering a researcher-first approach to vulnerability disclosure.
03 Aug 2026
JavaScript
★ 129
Noxen is an Android runtime interception tool designed for security researchers, leveraging Frida to dynamically hook Java methods within live Android processes. It enables the analysis of app component interactions by capturing events such as `Intent` objects, allowing users to inspect, modify, and control the flow of these events through a terminal user interface. Notable features include the ability to manipulate intent parameters, store session histories in project files, and utilize filters for intercepts and logs, enhancing the thoroughness of security assessments.
03 Aug 2026
TypeScript
★ 46
Monitoring Monster (MonMon) is an automation tool designed for bug bounty hunters that facilitates real-time monitoring of target systems for changes, such as new subdomains or scope expansions. Key features include a smart diff engine for tracking modifications across multiple endpoints, support for alerts via platforms like Slack and Discord, and a user-friendly dashboard that allows for comprehensive task management and historical data reviews. The tool is built in Go and supports easy deployment via Docker, enabling seamless integration into security workflows.
03 Aug 2026
Java
★ 12
Intigriti Quick Scope (IQS) is a Burp Suite extension that streamlines the project setup process by integrating with the Intigriti Researcher API, allowing users to import target scopes from bug bounty programs seamlessly. Key features include the ability to fetch available programs—including private ones—auto-configure Burp Suite with a single click, and inspect scope requirements like mandatory headers and rate limits. This tool enhances the efficiency of security testing for professionals engaged in bug bounty hunting.
03 Aug 2026
C
★ 31
The iOS 26 Activation Lock repository documents 31 firmware-level vulnerabilities found in iOS 26.3, specifically targeting the activation lock subsystem. It serves primarily as a resource for the security research community, featuring self-contained writeups for each vulnerability, ranking from critical to less severe, along with proof-of-concept implementations and exploitation scripts. Notable features include detailed descriptions, reproduction steps, and evidence for each finding, aiding researchers in understanding and possibly mitigating the identified security issues.
03 Aug 2026
Shell
★ 60
HuntTheBug is an advanced reconnaissance framework tailored for bug bounty hunters, combining over 30 security tools into a streamlined workflow to facilitate automated vulnerability discovery. Notable features include parallel execution for enhanced speed, live domain verification, real-time Telegram notifications for immediate alerts, and comprehensive scanning capabilities for subdomains, URLs, and directories. This toolkit is specifically optimized for use on Kali Linux, ensuring efficient and effective reconnaissance processes.
03 Aug 2026
Python
★ 10
Hgrab is a lightweight framework designed for scanning various web-based software applications over specified ports using minimal bandwidth. It supports a diverse set of applications, including VMware vCenter and Apache NiFi, enabling users to easily identify and interact with these services via simple command-line inputs. Notable features include the ability to list available software for scanning and the integration with external tools like ZMap for efficient scanning operations.
03 Aug 2026
CSS
★ 12
Hacker Library is an online platform designed specifically for hackers to discover and access a curated collection of essential books. Its primary use case is to facilitate the exploration of top literature in hacking and cybersecurity, promoting knowledge sharing within the community. Notably, the project emphasizes ease of access and organization, making it simple for users to find valuable resources.
03 Aug 2026
Python
★ 351
h1-brain is an MCP server designed to integrate your AI assistant with the HackerOne platform, facilitating the retrieval and analysis of your bug bounty history and program details via a local SQLite database. The tool offers features such as a pre-built database of over 3,600 publicly disclosed bounty reports and the ability to generate comprehensive attack briefings using the `hack(handle)` function, which consolidates personal findings, public disclosures, and suggests attack vectors in a single operation.
03 Aug 2026
Python
★ 41
H1 Asset Fetcher is a command-line tool designed for bug bounty hunters to efficiently fetch, download, and decompile mobile app assets from various bug bounty programs like HackerOne and Bugcrowd. It offers a user-friendly, interactive prompt to guide users through selecting assets across Android, iOS, and executable files, with features including bulk downloading, asset decompilation using JADX, and credential management for streamlined repeated usage.
03 Aug 2026
Python
★ 2238
Gpt-Agreement-Payment is an end-to-end replay tool designed for automating the subscription process of ChatGPT Plus and Team through various payment pathways, including Stripe Checkout, PayPal, GoPay, and QRIS. It incorporates features such as a visual solver for hCaptcha, anti-fraud empirical data collection, and a concurrent worker system for handling multiple OTP requests efficiently. This tool is primarily aimed at CTF and bug bounty environments, requiring adherence to strict legal usage guidelines.
03 Aug 2026
Python
★ 15
gitghost is a tool designed to scan public GitHub repositories for exposed secrets, including those that may have been committed in the past and then deleted. It thoroughly searches through git history to identify vulnerabilities and presents findings in an HTML report complete with direct links to the locations of the secrets, as well as a guide on how to remediate the issues. Notable features include the ability to generate an exposure score, scan for various types of sensitive information, and run local scans without installation.
03 Aug 2026
JavaScript
★ 84
Frida Setup is an installer script designed to facilitate the bypass of SSL pinning in Android applications by automating the installation of Frida and configuring Burp's certificate. The tool is primarily used with Genymotion Emulator or an appropriately configured ADB environment, enabling seamless interaction for SSL interception. Notable features include automatic installation of Frida and its tools, fetching the latest Frida server, downloading Burp's proxy certificate, and cleaning up post-installation requirements for a clean workflow.
03 Aug 2026
Python
★ 100
favicon_hash_shodan is a tool designed to identify and retrieve all hosts sharing the same favicon by leveraging Shodan's search capabilities. Its primary use case is to aid cybersecurity professionals in uncovering potential target infrastructure or tracking down related web services by analyzing favicon hashes. Notable features include a simple command-line interface for direct usage, integration with Shodan for result viewing, and an uncover mode to enhance search capabilities.
03 Aug 2026
Python
★ 22
FastRecvSMS is an SMS verification toolkit designed for security professionals, enabling the purchase of temporary phone numbers to receive SMS codes via a command-line interface (CLI). Key features include support for multiple providers, real-time SMS monitoring, automatic waiting for verification codes, and secure configuration management using local TOML files. The tool streamlines the process of obtaining and verifying SMS codes for various services, making it efficient for testing and security assessments.