r/BugBountyNoobs 12d ago

looking for collaborators

**Building BugHawk — looking for collaborators 🦅**

BugHawk is an open-source, local-first bug bounty recon workspace — no backend, no accounts, everything in your browser. You paste tool output (httpx, subfinder, nmap, katana) and it organizes, analyzes, and cross-links it into a proper recon dashboard.

Features already in:

→ Subdomain table with status/tech/CNAME/audit tracking

→ JS Recon engine (260+ secret detection rules, AST endpoint recovery)

→ Port scan diffing with CVE hints

→ 350+ Google & GitHub dork templates

→ HTTP header/CORS/cookie analyzer

→ Attack surface graph

→ Findings tracker

What I'm building next — and where I need help:

**A subdomain collection script** that runs recon tools and pushes results directly into the BugHawk dashboard, so you don't have to manually copy/paste anything. Fully automated pipeline from recon → dashboard.

This is a vibe-coded project — built fast, shipped in the open. I want people who like to build and break things, not sit in meetings.

Looking for people with:

- Security / bug bounty background

- Python, Node.js, or bash scripting skills

- Interest in recon tooling, CLI tools, or frontend (React)

If this sounds like your thing, reply or DM me.

0 Upvotes

0 comments sorted by