Skip to content

Repository files navigation

Bug Bounty Hunting Toolkit 🎯

CI Release

A comprehensive AI-enhanced toolkit for ethical bug bounty hunting on platforms like Bugcrowd and HackerOne.

🤖 NEW: AI-Powered Features

This toolkit now includes Ollama Cloud AI integration for:

  • 🧠 Intelligent vulnerability analysis
  • 🎯 False positive detection
  • 📊 AI-generated reports
  • 🔍 JavaScript code analysis
  • 💡 Context-aware payload suggestions

📖 See AI Features Documentation | 🚀 Quick Setup Guide

⚠️ IMPORTANT LEGAL NOTICE

ONLY use these tools on:

  • Programs you have explicit permission to test
  • Targets listed in bug bounty programs you've joined
  • Your own systems for practice

Unauthorized testing is ILLEGAL and can result in criminal charges.

🎯 Project Structure

bug_bounty_toolkit/
├── recon/              # Reconnaissance tools
├── scanners/           # Vulnerability scanners
├── exploits/           # Proof of concept scripts
├── reports/            # Report templates
├── wordlists/          # Custom wordlists
├── results/            # Scan results (gitignored)
└── tools/              # Utility scripts

🚀 Quick Start

Traditional Mode (No AI)

  1. Install dependencies:

    pip install -r requirements.txt
  2. Run vulnerability scan:

    python tools/vulnerability_scanner.py -t target.com

AI-Enhanced Mode (Recommended)

  1. Install dependencies:

    pip install -r requirements.txt
  2. Configure Ollama Cloud:

    cp .env.example .env
    # Edit .env and add your OLLAMA_API_KEY

    Get your API key and setup instructions →

  3. Run AI-enhanced scan:

    python tools/ai_vulnerability_scanner.py -t target.com
  4. Generate AI report:

    python reports/ai_report_generator.py -i results/target.com_ai_comprehensive_report.json

Example commands

# Scan multiple targets from a file and save each run in its own folder
while read -r target; do
  python tools/vulnerability_scanner.py -t "$target" -o "results/$target"
done < targets.txt

# Save AI scan output to a custom path for later reporting
python tools/ai_vulnerability_scanner.py -t https://example.com -o results/example_ai

# Toggle AI analysis off while keeping the AI workflow flags handy
python tools/ai_vulnerability_scanner.py -t api.target.com --no-ai --skip-recon

🔍 Methodology

Phase 1: Reconnaissance

  • Subdomain enumeration
  • Port scanning
  • Technology fingerprinting
  • Directory/file discovery
  • Parameter discovery
  • JavaScript analysis

Phase 2: Vulnerability Scanning

  • XSS (Cross-Site Scripting)
  • SQL Injection
  • CSRF (Cross-Site Request Forgery)
  • SSRF (Server-Side Request Forgery)
  • Open Redirects
  • Authentication bypasses
  • API vulnerabilities
  • File upload vulnerabilities

Phase 3: Exploitation & Reporting

  • Proof of concept development
  • Impact assessment
  • Professional report writing

📚 Learning Resources

🛠️ Tools Included

Core Scanners

  • Reconnaissance: Subdomain finder, port scanner, tech detector
  • Scanners: XSS, SQLi, SSRF, open redirect detectors
  • Utilities: Request interceptor, payload generator, report builder

AI-Enhanced Tools ✨

  • AI Vulnerability Scanner: Comprehensive scanner with AI analysis
  • AI XSS Scanner: JavaScript analysis with DOM XSS detection
  • AI Report Generator: Beautiful reports with AI insights
  • AI Analyzer: Standalone AI analysis tool
  • False Positive Detector: Automatic FP detection with confidence scoring

📝 Reporting

Traditional Reports

Use the templates in reports/ to create professional vulnerability reports.

AI-Enhanced Reports ✨

Generate comprehensive reports with:

  • Executive summaries in natural language
  • AI-powered vulnerability analysis
  • Exploitability scoring
  • False positive warnings
  • Beautiful HTML reports
  • Prioritized recommendations
python reports/ai_report_generator.py -i results/scan_results.json

🔐 Ethics & Responsibility

  • Always follow the bug bounty program's scope
  • Never access or modify data you don't own
  • Report vulnerabilities responsibly
  • Don't perform DoS attacks
  • Respect rate limits and system resources

📄 License

For educational and authorized security testing only.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages