0xHunt

// bug bounty tools, by g3ksec

0xHunt

An ecosystem of independent security tools, built by and for the bug bounty community. Not one product — three, so far, and counting.

Explore the tools

// the tools

The tools

Three separate projects, each with its own repo. Open the one you need.

~/0xhunt/0xbugletter

0xBugLetter

Active
Content

Curated archive of verified bug bounty writeups — findings timeline, community metrics, and a bot that posts new finds to Discord.

~/0xhunt/0xhashfavicon

0xHashFavicon

Active
Recon

Extracts Shodan/Fofa-compatible MurmurHash3 signatures from any favicon — for asset discovery and mapping hidden attack surface.

~/0xhunt/0xbuglabs

0xBugLabs

Beta
Training

Self-hosted Docker labs for practicing IDOR, XSS, SSRF, auth flaws, and OSINT — real apps with multiple objectives, nothing telegraphed in the UI.

// what's next

More tools, in the pipeline.

Next tool is still taking shape — no name, no date yet.

It'll show up here, next to the others, once it's real.

// why this exists

I built these for myself first.

Each tool solves a problem I actually had while hunting: a faster way to fingerprint a favicon, one place to keep my writeups instead of scattered bookmarks, a lab to test an idea before trying it on a real target. 0xHunt exists to list them in one place — nothing more.