Try searching for "database", "file", "API", or browse by category
77 Tools in Bug Bounty
jwtauditor
by dr34mhacks
JWT Auditor – Analyze, break, and understand your tokens like a pro.
xurlfind3r
by hueristiq
A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directly with the target but instead gathers data that is already publicly available.
Nuclei-AI-Prompts
by reewardius
Nuclei-AI-Prompts
BugBountyScanner
by chvancooten
A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
unfurl
by tomnomnom
Pull out bits of URLs provided on stdin
http-request-smuggling
by anshumanpattnaik
HTTP Request Smuggling Detection Tool
clairvoyance
by nikitastupin
Obtain GraphQL API schema even if the introspection is disabled
ZoomeyeSearch
by RevoltSecurities
A powerful CLI tool that uses ZoomEye to search exposed services, gather intelligence, and automate reconnaissance.
NucleiPrompt
by AryaSec1337
Nuclei Prompt Scanner adalah tools berbasis Python yang memanfaatkan Nuclei dan AI Prompting untuk melakukan pemindaian kerentanan pada web target berdasarkan kategori OWASP dan lainnya, dengan antarmuka interaktif berbasis CLI (command-line).
altdns
by infosec-au
Generates permutations, alterations and mutations of subdomains and then resolves them
awesome-bugbounty-builder
by 0xJin
Awesome Bug bounty builder Project
awesome-oneliner-bugbounty
by dwisiswant0
A collection of awesome one-liner scripts especially for bug bounty tips.
burp_bug_finder
by lucsemassa
Automatic Bug finder with buprsuite
apidetector
by brinhosa
APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and flexible input/output options. Ideal for API security testing.
Recon-Search-Assistant
by Boopath1
A powerful and intuitive web-based search engine designed specifically for bug bounty hunters and security researchers. This tool provides quick access to various Google dorks and specialized searches to help identify potential security vulnerabilities and gather information about target domains.
Infosec Certifications Resources
Discover the best cybersecurity certifications to advance your career








































Frequently Asked Questions about InfosecMania
Learn more about Cybersecurity Tools and how they can enhance your security posture
InfoSecMania is a comprehensive directory of cybersecurity tools and resources designed to help security professionals find the right tools for their needs.
You can submit a tool by clicking on the 'Submit Tool' link in the navigation menu and filling out the submission form with details about your tool.
Feel free to connect with us on LinkedIn, Discord, or just write to us at [email protected].
Tools are categorized based on their primary function, such as penetration testing, vulnerability assessment, network security, etc. Many tools may appear in multiple categories if they serve multiple purposes.
We only list tools and resources from publicly available, reputable sources — most of which are open-source and widely used in the cybersecurity community. However, always review and test tools in a safe, legal environment, like your lab or VM.
We actively monitor public repositories, GitHub, and community forums to keep our tool listings fresh. Many tools are auto-sourced from open-source feeds and security communities.