# trickest/inventory

Asset inventory of over 800 public bug bounty programs.

Repository: https://github.com/trickest/inventory
Canonical: https://ross.abutalabs.com/products/inventory
Homepage: https://trickest.com
Language: Shell
License: MIT
License Family: permissive
Topics: security, bugbounty, bugbountytips, infosec, reconnaissance, recon, pentesting, hacking, security-tools, red-team, penetration-testing, software-security, pentest-tool, osint, osint-tool, osint-resources, threat-intelligence, bug-bounty, fuzzing
Last push: 2025-02-14T20:23:58+00:00

## Health v2 (maintenance only)
Score: 35/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 6, release rhythm 35, longevity 100
- inputs: {"age_days": 1647, "days_push": 565, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1602, forks 281 (observed 2026-08-28T04:05:09.737184+00:00)

## What it is
A continuously updated asset inventory of over 800 public bug bounty programs, including DNS and web server data, maintained by Trickest. It consolidates program data from multiple sources into a targets. file to help bug bounty hunters and security teams discover and monitor assets.

## Use cases
- find assets for new bug bounty programs quickly
- get a list of in-scope domains for public bug bounty programs
- monitor companies for newly added assets
- reduce noisy automated scanning by reusing scheduled recon results
- feed bug bounty target lists into recon pipelines
- give security teams visibility into their public attack surface

## When to choose
- you are a bug bounty hunter starting on new programs and need up-to-date target lists
- you want a consolidated JSON dataset of public bug bounty program domains
- you want to avoid re-running noisy automated scans against programs yourself

## When to avoid
- you need private or invitation-only bug bounty program data
- you need real-time vulnerability scanning rather than asset inventory data
- you need a managed attack surface monitoring product rather than a dataset

## Facets
- artifact type: dataset
- maturity: active
- function: security, osint, monitoring, data-science
- domain: security, osint, penetration-testing
- platform: cross-platform, cli
- tags: bug-bounty, attack-surface-management, recon, asset-inventory, threat-intelligence, red-team

## Member repositories
- trickest/inventory (main) score 35

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:09.737184+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:52:38.272334+00:00, confidence not recorded.
  - readme: https://github.com/trickest/inventory (fetched 2026-08-28T04:05:09.737184+00:00, sha 172999f83676)
  - homepage: https://trickest.com (fetched 2026-08-29T11:24:19.872177+00:00, sha e7343ce3c591)
  - site_page: https://trickest.com/docs/introduction (fetched 2026-08-29T11:24:19.878201+00:00, sha ce06621f5c50)
  - site_page: https://trickest.com/docs/releases/changelog (fetched 2026-08-29T11:24:19.879767+00:00, sha 9027fd231153)
  - site_page: https://trickest.com/about-us (fetched 2026-08-29T11:24:19.883126+00:00, sha a4955c35541b)
  - site_page: https://trickest.com/pricing (fetched 2026-08-29T11:24:19.876450+00:00, sha dd1333d2be9e)
  - site_page: https://trickest.com/platform/cli (fetched 2026-08-29T11:24:19.884801+00:00, sha b82aef12b4ca)
- Data as of 2026-08-30T08:39:29.467469+00:00.
