A comprehensive AI-enhanced toolkit for ethical bug bounty hunting on platforms like Bugcrowd and HackerOne.
This toolkit now includes Ollama Cloud AI integration for:
- 🧠 Intelligent vulnerability analysis
- 🎯 False positive detection
- 📊 AI-generated reports
- 🔍 JavaScript code analysis
- 💡 Context-aware payload suggestions
📖 See AI Features Documentation | 🚀 Quick Setup Guide
ONLY use these tools on:
- Programs you have explicit permission to test
- Targets listed in bug bounty programs you've joined
- Your own systems for practice
Unauthorized testing is ILLEGAL and can result in criminal charges.
bug_bounty_toolkit/
├── recon/ # Reconnaissance tools
├── scanners/ # Vulnerability scanners
├── exploits/ # Proof of concept scripts
├── reports/ # Report templates
├── wordlists/ # Custom wordlists
├── results/ # Scan results (gitignored)
└── tools/ # Utility scripts
-
Install dependencies:
pip install -r requirements.txt
-
Run vulnerability scan:
python tools/vulnerability_scanner.py -t target.com
-
Install dependencies:
pip install -r requirements.txt
-
Configure Ollama Cloud:
cp .env.example .env # Edit .env and add your OLLAMA_API_KEY -
Run AI-enhanced scan:
python tools/ai_vulnerability_scanner.py -t target.com
-
Generate AI report:
python reports/ai_report_generator.py -i results/target.com_ai_comprehensive_report.json
# Scan multiple targets from a file and save each run in its own folder
while read -r target; do
python tools/vulnerability_scanner.py -t "$target" -o "results/$target"
done < targets.txt
# Save AI scan output to a custom path for later reporting
python tools/ai_vulnerability_scanner.py -t https://example.com -o results/example_ai
# Toggle AI analysis off while keeping the AI workflow flags handy
python tools/ai_vulnerability_scanner.py -t api.target.com --no-ai --skip-recon- Subdomain enumeration
- Port scanning
- Technology fingerprinting
- Directory/file discovery
- Parameter discovery
- JavaScript analysis
- XSS (Cross-Site Scripting)
- SQL Injection
- CSRF (Cross-Site Request Forgery)
- SSRF (Server-Side Request Forgery)
- Open Redirects
- Authentication bypasses
- API vulnerabilities
- File upload vulnerabilities
- Proof of concept development
- Impact assessment
- Professional report writing
- Reconnaissance: Subdomain finder, port scanner, tech detector
- Scanners: XSS, SQLi, SSRF, open redirect detectors
- Utilities: Request interceptor, payload generator, report builder
- AI Vulnerability Scanner: Comprehensive scanner with AI analysis
- AI XSS Scanner: JavaScript analysis with DOM XSS detection
- AI Report Generator: Beautiful reports with AI insights
- AI Analyzer: Standalone AI analysis tool
- False Positive Detector: Automatic FP detection with confidence scoring
Use the templates in reports/ to create professional vulnerability reports.
Generate comprehensive reports with:
- Executive summaries in natural language
- AI-powered vulnerability analysis
- Exploitability scoring
- False positive warnings
- Beautiful HTML reports
- Prioritized recommendations
python reports/ai_report_generator.py -i results/scan_results.json- Always follow the bug bounty program's scope
- Never access or modify data you don't own
- Report vulnerabilities responsibly
- Don't perform DoS attacks
- Respect rate limits and system resources
For educational and authorized security testing only.