Skip to content
View codehunt2's full-sized avatar

Block or report codehunt2

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Python 1,873 235 Updated May 20, 2024

An HTTP toolkit for security research.

Go 11,275 706 Updated Feb 5, 2025

Remove duplicates from MASSIVE wordlist, without sorting it (for dictionary-based password cracking)

C++ 972 95 Updated Nov 4, 2025

This repo contain scripts written for finding subdomains using various available tools

Shell 27 10 Updated Oct 21, 2020

Mobile application testing toolkit

Python 247 54 Updated Nov 8, 2018

Bug Bounty Roadmaps

1,718 295 Updated Jun 12, 2021

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

HTML 314 81 Updated Jun 1, 2022

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

CSS 11,653 3,118 Updated Jun 16, 2026

Top disclosed reports from HackerOne

Python 6,252 1,115 Updated Jun 11, 2026

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Python 5,420 979 Updated Mar 13, 2026

Collection of methodology and test case for various web vulnerabilities.

7,144 1,931 Updated Jun 25, 2025

A tool to find subdomains or domains from passive sources.

Rust 112 15 Updated Jan 20, 2021

Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.

Dockerfile 766 159 Updated Mar 11, 2022

Docker image that provides features similar to Burp Collaborator

Dockerfile 15 4 Updated Mar 6, 2021

Automation for javascript recon in bug bounty.

Shell 1,092 188 Updated Sep 9, 2023

My CodeQL repository.

CodeQL 3 Updated Aug 14, 2020

take a list of old subdomain and new subdomain and the output is the deleted subdomain and the new subdomain

Shell 9 4 Updated Jun 28, 2020

BBT - Bug Bounty Tools (examples💡)

Python 1,900 469 Updated Apr 5, 2024

Lesser Known Web Attack Lab

CSS 330 47 Updated Feb 7, 2020

A Modern Orchestration Engine for Security

Go 6,421 1,015 Updated Jun 1, 2026

RECON Notes taking from every fucking book about bugbounty and web-app penetration testing exists

19 6 Updated Feb 29, 2020

Secret and/or credential patterns used for gf.

Shell 245 52 Updated Feb 10, 2023

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

Go 4,976 508 Updated Mar 20, 2026

A one liner Bash command which finds CORS in every possible endpoint.

152 43 Updated Jan 1, 2021

A Payload Injector for bugbounties written in go

Go 70 26 Updated Jul 18, 2020

Awesome list dedicated to Windows Subsystem for Linux

6,359 304 Updated May 26, 2026

Cross-site scripting labs for web application security enthusiasts

PHP 341 48 Updated Jun 2, 2021

A collection of all the data i could extract from 1 billion leaked credentials from internet.

3,267 419 Updated Jul 1, 2020

Bug Bounty stuffs, payloads, scripts, profiles, tips and tricks, ...

BitBake 147 33 Updated Jul 30, 2020
Next