cyberstars
cyberstars / purpose / bug-bounty

Tools for bug bounty

Independent disclosure programs.

73 tools indexed

AI-driven single-binary pentest agent from the chainreactors toolkit

ScanExploitNetworksWeb apps
GoAGPL-3.0

Image-scaling attacks for multi-modal LLMs.

ExploitFuzzWeb apps
PythonAGPL-3.0

On-device reverse engineering suite for Android.

AnalyzeMobile appsBinaries

Automated external attack-surface mapping.

ReconAutomateWeb appsNetworks
PythonGPL-3.0

Agentic platform for automated source-code vulnerability discovery.

ScanAnalyzeSource code
PythonAGPL-3.0

BBOT

Recursive internet scanner for recon and attack-surface mapping.

ScanReconWeb appsNetworks
PythonAGPL-3.0

Bridge between Burp Suite and Frida

InterceptAnalyzeMobile apps
JavaMIT

Drive Burp Suite from an LLM.

AutomateScanWeb apps
JavaApache-2.0

Fast CORS misconfig scanner.

ScanWeb apps
PythonGPL-3.0

Find public exploits and PoCs for a given CVE ID.

ReconNetworksEndpoints
PythonGPL-3.0

Web vulnerability scanner with custom POCs.

ScanWeb apps
Custom

OS command-injection exploitation.

ExploitScanWeb apps
PythonGPL-3.0

Cook

Wordlist framework for hackers.

ReconAutomateWeb appsNetworks
GoMIT

Parameter-aware XSS scanner.

ScanFuzzWeb apps
GoMIT

Advanced web path scanner.

FuzzReconWeb apps
PythonGPL-2.0

Full toolkit for next-level domain and DNS analysis.

ReconScanNetworksWeb apps
TypeScriptAGPL-3.0

Microsoft's private out-of-band (OAST) security testing platform

ScanMonitorWeb appsNetworks
MIT

Autonomous white-hat security auditor built on coding agents.

AnalyzeExploitSource codeWeb apps
TypeScriptAGPL-3.0

Dynamic instrumentation for app analysis.

AnalyzeInterceptMobile appsBinaries
CwxWindows

Advanced automatic SQL injection detection and exploitation

ExploitScanWeb apps
PythonMIT

Directory, DNS and vhost brute-forcer.

FuzzReconWeb appsNetworks
GoApache-2.0

Generate gopher:// SSRF payloads.

ExploitWeb apps
PythonMIT

Open-source HTTP toolkit for sec research.

InterceptScanWeb apps
GoMIT