- Simple Chrome extension to assist in testing for things like xss, etc.
- Chrome extension for XSS Hunter Payloads.
- A python api client for Bugcrowd.
- Finds all public bug reports on Hackerone.
- A python 2.7 script using Tornado and JSBeautifier to parse relative URLs from JavaScript files.
- Python script to scrape specified web page(s) for external links and verify whether or not it is an active resource.
- A python script that finds endpoints in JavaScript files.
- Stay on top of new subdomains! Bug bounty hunters can use this tool to receive Pushbullet notifications each time there is a new target subdomain.
- A fuzzing engine and fuzz testing framework consisting of multiple extensible components.
- A great way to long term track your bug hunting achievements.
- A modern, browser-based frontend to gdb (gnu debugger). Add breakpoints, view stack traces, and more in C, C++, Go, and Rust. Simply run gdbgui from the terminal and a new tab will open in your browser.
- A tool for visualizing binary data using a color palette.
- Pure Python parser and analyzer for IDA Pro database files (.idb).
- An IDA Pro plugin for exporting disassemblies into BinNavi databases and to Protocol Buffers.
- Grep through binaries with colorized results.
- Transceiver for Hella wireless car key fobs.
- IDAPython scripts for automating analysis of firmware of embedded devices.
- Prevent blindness from IDA Pro's default skin.
- Code Coverage Explorer for IDA Pro.
- Tools for working with codeplugs and firmware of the Tytera MD380. The wiki has a ton of documentation as well.
- A toolset for reverse engineering and fuzzing Protobuf-based apps.
- A Python scriptable Reverse Engineering sandbox make by Cisco Talos.
- A radare2 Plugin to perform symbolic execution with a simple macro call. Internally it uses angr as execution engine. The Usage is possible with and without debugger, dynamic and static analysis mode.
- Unix-like reverse engineering framework and commandline tools.
- Seed recovery tool for PRNGs.
- Ask Me Anything with the current top bug hunter on BugCrowd.
- A comprehensive curated list of Bug Bounty Programs and write-ups from the Bug Bounty hunters.
- A list of bug bounty write-up that is categorized by the bug nature, this is inspired by Awesome Bug Bounty.
Bughunter University (Google)
- Great little write-up by Bug Crowd.
How to become a successful Bug Bounty Hunter
Radare2 Dubugger Complete Cheat Sheet
Researcher Resources - How to become a Bug Bounty Hunter
Reverse Engineering for Beginners
Reverse Engineering Malicious Code Tips
Scrutiny on the Bug Bounty (Slides)