Ross ROSS = Recommend OSS · open-source software intelligence for agents

jhaddix/tbhm resource

The Bug Hunters Methodology observed · 2026-08-28

github.com/jhaddix/tbhm observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4055
  • days_rel: n/a
  • days_push: 1128
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

4396 stars · 835 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A curated collection of tips, tricks, tools, and notes for web application security assessments and bug bounty hunting, maintained by Jason Haddix. It accompanies his well-known 'Bug Hunter's Methodology' conference talks and organizes resources by hacking phases like reconnaissance, mapping, and tactical fuzzing.

Use cases

  • learning web application security from scratch
  • finding bug bounty recon methodology and tools
  • preparing for a web app penetration test
  • looking up XSS and SQLi fuzzing techniques
  • finding learning resources and content creators for ethical hacking
  • building a bug hunting workflow

When to choose

  • you want a curated, opinionated starting point for bug bounty hunting
  • you need a structured methodology covering recon through exploitation
  • you prefer learning from conference-tested material by a known practitioner

When to avoid

  • you need runnable software or tooling rather than notes and links
  • you require an actively updated resource with recent commits
  • you need formal documentation or a license-governed codebase

Facets

learning-resource · maturity maintenance

security penetration-testing developer-tools security penetration-testing web-development cross-platform bug-bounty web-security reconnaissance vulnerability-assessment notes awesome-list

1 source

Member repositories

RepositoryRoleHealth v2
jhaddix/tbhmmain32

For agents

markdown · JSON · MCP: product_card(name="jhaddix/tbhm")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem