03 Aug 2026
Python
★ 10
ExplorerPy is an information-gathering reconnaissance toolkit that enables users to perform subdomain enumeration, directory brute-forcing, and port scanning on a specified domain. It features multithreaded execution for enhanced performance, customizable options for wordlists and timeouts, as well as capabilities for User-Agent and HTTP header spoofing to simulate legitimate requests. This tool is designed for both educational and testing purposes, ensuring a comprehensive approach to domain analysis.
03 Aug 2026
Python
★ 42
DarkBuster is an advanced web directory and file brute-forcing tool designed for authorized security testing, featuring multithreading capabilities to optimize scan speed. It includes curated wordlists updated to May 2026, supports customizable extensions, and offers a user-friendly CLI interface with color-coded output and real-time progress tracking. Notable features include the ability to save results, use custom headers, and specify various scanning options to enhance the pentesting process.
03 Aug 2026
Python
★ 24
Crivo is an open-source Python tool tailored for offensive security analysts, pentesters, and bug bounty hunters, facilitating the extraction and filtering of URLs, IPs, domains, and subdomains from various text inputs and web pages. Notable features include built-in web scraping, flexible scope filtering, and clean output formatting for easy integration into automated workflows, making it efficient for processing data and generating organised reports.
03 Aug 2026
Shell
★ 22
Claude Security Research Skill enhances the Claude AI with structured security assessment workflows, enabling it to effectively manage and execute security research across multiple phases, including reconnaissance, vulnerability scanning, and reporting. Notable features include tool chaining, automated phase management based on target types, and the capability for Claude to interpret tool outputs, suggest subsequent actions, and compile professional assessment reports. This skill integrates seamlessly into Claude's environment, facilitating detailed and methodical security assessments without generating payloads or exploit code.
03 Aug 2026
Vim Snippet
★ 27
Claude Code DeepSeek is a command-line interface tool designed to interact with DeepSeek's Anthropic-compatible API, specifically aimed at security researchers and bug bounty hunters. It supports headless operation, allowing automation on VPS without OAuth, and features two model options for varying workloads—`deepseek-v4-pro` for complex reasoning and `deepseek-v4-flash` for faster, background tasks. The tool facilitates seamless integration into CI pipelines, offering cost-effective usage with a pay-per-token model, devoid of rate limits inherent to traditional subscriptions.
03 Aug 2026
Shell
★ 38
Claude CyberSecurity Skills integrates Claude Code to assist bug bounty hunters on platforms like HackerOne and Bugcrowd through an automated end-to-end workflow encompassing reconnaissance, vulnerability hunting, validation, and reporting. The tool offers 30 production-grade skills that utilize real tools and custom payloads, allowing users to efficiently execute tasks by simply describing their objectives. Notable features include tailored report templates and a systematic approach to vulnerability identification across multiple phases including pre-hunt, reconnaissance, and vulnerability validation.
03 Aug 2026
Kotlin
★ 210
BurpMCP-Ultra is a powerful Kotlin extension for Burp Suite Professional that integrates an MCP server, enabling programmatic control of Burp functionalities via AI agents. It supports 149 structured tools for tasks such as proxy history analysis, scan management, fuzzing, and guided exploitation, all secured through token-based local transport. Notable features include custom scan checks, an extensive real-time dashboard, and hardened localhost security controls.
03 Aug 2026
Python
★ 25
JSReconRadar is a robust Burp Suite extension designed for passive reconnaissance of JavaScript files, enabling the detection of secrets, API keys, endpoints, and security misconfigurations in real-time. It features over 1,600 detection patterns, customizable UI elements, advanced filtering options, and supports both Burp Suite Community and Professional editions, making it essential for identifying vulnerabilities in web applications. Noteworthy functionalities include a custom results tab, severity color coding, and the capability to save or export findings for further analysis.
03 Aug 2026
HTML
★ 49
BugBoard is an open-source web application that acts as a centralized dashboard for cybersecurity tools, enabling users to efficiently identify and report vulnerabilities such as SQL Injection, XSS, and CSRF. Its modular design allows users to focus on specific vulnerabilities while providing a user-friendly interface that caters to both novices and experienced professionals in the bug bounty process. Notable features include comprehensive vulnerability assessments and an intuitive layout for streamlined navigation.
03 Aug 2026
JavaScript
★ 14
BlackInspect is a versatile Tampermonkey userscript that integrates an extensive suite of web inspection, spoofing, and hacking tools directly into any webpage. Its primary use case includes tasks such as real-time server data analysis, JavaScript variable manipulation, advanced password management, and the ability to inject arbitrary JavaScript code while also providing features like canvas fingerprint spoofing and XSS injection. Key functionalities include a customizable floating panel, automated setting storage, and domain-specific restriction breaking, catering to cybersecurity professionals and enthusiasts alike.
03 Aug 2026
★ 551
Awesome Real-time Communications Security is a comprehensive resource repository intended for researchers and practitioners focusing on the security of VoIP, WebRTC, and VoLTE technologies. It provides an organized collection of tools, papers, and educational materials that facilitate penetration testing and vulnerability assessment in real-time communication systems. Notable features include categorization of open-source and commercial tools, along with continuous updates to ensure relevance and accessibility of the resources.
03 Aug 2026
Python
★ 16
AdwanceSNI is a command-line tool designed for subdomain discovery and vulnerability scanning on Termux and Linux platforms. Leveraging the capabilities of subfinder for subdomain enumeration and bughunter-go for vulnerability analysis, it features a user-friendly colorful terminal UI, progress indicators, and supports batch processing for multiple domains. This tool is primarily intended for educational and ethical hacking purposes, emphasizing user responsibility for permissions when scanning targets.
03 Aug 2026
Perl
★ 18
The Admin Control Panel Finder is a Perl-based tool designed to identify potential admin login paths on websites, catering primarily to developers and security professionals for authorized testing. It automatically checks common admin panel URLs across various web technologies, such as PHP and ASP, and employs keyword detection for typical login fields, making it a lightweight and beginner-friendly tool for ethical hacking and cybersecurity education.
03 Aug 2026
★ 75
The pkgforge-security/Wordlists repository provides a comprehensive collection of wordlists optimized for various cybersecurity tasks, primarily focusing on API discovery, DNS subdomain enumeration, and low-hanging fruit exploitation. Notable features include multiple categorized lists such as "tiny," "mini," and "massive," which offer different scopes of keywords suited for fuzzing and brute-forcing scenarios. The tool allows users to easily download specific lists via curl or wget commands for enhanced efficiency in penetration testing and vulnerability assessment.
03 Aug 2026
Shell
★ 106
TIKTOK-SSL-Pinning-Bypass is a tool designed for security researchers and developers to bypass SSL certificate pinning in the TikTok app on Android devices, facilitating the interception and analysis of HTTPS traffic. Its notable features include compatibility with both rooted and non-rooted devices, support for various proxy tools, and recent enhancements that allow full functionality on Android 11 and above, including the capture of login and registration traffic. The tool provides a pre-patched TikTok APK, enabling users to inspect API calls and the app's network interactions seamlessly.
03 Aug 2026
Shell
★ 16
Threads SSL Pinning Bypass allows users to bypass SSL certificate pinning in the Meta Threads app on Android, enabling the interception and analysis of HTTPS traffic through various proxy tools like Burp Suite and mitmproxy. This project provides a pre-patched APK compatible with both rooted and non-rooted devices, ensuring that security researchers and penetration testers can effectively capture network requests and API responses for version 440.0.0.47.86. Notable features include support for multiple architectures and detailed setup instructions for both physical devices and emulators.
03 Aug 2026
Python
★ 257
RustChain Bounties facilitates user engagement in the RustChain ecosystem by offering a bounty program where contributors can earn RTC (RustChain Token) for completing various tasks. The tool supports multiple categories, including code, content, and security-related tasks, providing clear difficulty ratings and compensation structures, thus incentivizing participation from both experienced developers and newcomers. Notable features include an extensive list of open bounties, specific payout procedures, and a comprehensive security protocol to safeguard against fraud.
03 Aug 2026
Python
★ 17
ReconFusionAI is an AI-powered web asset scanner designed to detect exposed secrets, credentials, PII, and vulnerabilities across web applications with high accuracy through a comprehensive library of over 1,183 detection patterns. Its notable features include advanced contextual analysis using Ollama for improved understanding of data context, a modular architecture allowing for easy updates, and dual output formats that provide detailed findings and reconnaissance intelligence. Additionally, it incorporates intelligent caching mechanisms and production-hardened capabilities for efficient and robust operation.
03 Aug 2026
Python
★ 33
ReconForge is an AI-assisted reconnaissance toolkit designed for bug bounty hunters and security researchers, facilitating rapid transition from raw data to actionable insights. It features subdomain discovery, DNS enumeration, SSL/TLS analysis, Shodan integration, and technology detection, all complemented by AI triage prompts for analyzing HTTP responses and generating professional markdown reports. The tool emphasizes a speed-oriented, production-ready design with robust error handling and comprehensive testing capabilities.
03 Aug 2026
TypeScript
★ 16
Policymaker is an open-source tool that facilitates the rapid creation of vulnerability-disclosure policies, safe harbor clauses, and security.txt files without the need for legal assistance. It streamlines the process through a user-friendly wizard, producing defensible documents based on standardized, lawyer-reviewed language sourced from the dioterms framework. Key features include support for DNS Security TXT records and complete public domain output, ensuring compliance with current vulnerability disclosure standards.
03 Aug 2026
★ 312
The Penetration Testing Roadmap provides a comprehensive learning path designed to transition individuals from beginner to junior penetration tester by covering essential topics, tools, and hands-on labs. It is structured into phases, including foundational skills, web and infrastructure security, specialization tracks, and certification preparation. Notable features include a live roadmap, curated guides for various subjects, and links to practice labs and certifications, facilitating an organized and effective learning experience.
03 Aug 2026
Perl
★ 11
Parrot Recon is an automation script designed for reconnaissance in bug bounty scenarios, chaining multiple enumeration and vulnerability scanning tools into a single execution. It supports a range of scan types, including API and web scanning, and outputs comprehensive results to a specified directory. Notable features include support for various data sources such as Postman collections, extensive built-in scan capabilities, and the ability to run multiple scans sequentially while handling missing tools gracefully.
03 Aug 2026
Shell
★ 88
The orgs-data repository is designed to assist bug bounty hunters in identifying leaked secrets, vulnerabilities in GitHub Actions workflows, and conducting reconnaissance by gathering information from organizations' repositories. Notable features include scripts for listing GitHub organization names and tracking programs for potential vulnerabilities, along with a collaborative approach to maintain an up-to-date database of organizations and bug bounty programs.
03 Aug 2026
JavaScript
★ 2051
open·kritt is an open-source security research platform designed to orchestrate AI agents for the identification and validation of vulnerabilities in code repositories. It enables users to create custom workflows for security research, run scans on local or remote codebases, and prioritize findings with configurable severity rankings and automatic de-duplication. Notably, it supports integration with various AI model providers, allowing for flexible model access and requiring minimal setup for operation.
03 Aug 2026
Shell
★ 13
Meta Business Suite SSL Pinning Bypass is a tool designed to circumvent SSL/TLS certificate pinning for the Meta Business Suite application on Android devices, allowing for the interception and analysis of HTTPS traffic using various proxy tools like Burp Suite and mitmproxy. The tool is compatible with both rooted and non-rooted Android devices, and it supports multiple architectures, enabling users to capture and debug network requests effectively. Notable features include a step-by-step setup guide and the provision of a patched APK for seamless operation.