{"repo":"Mr-Destroyer/endpointhunter","free":true,"listed":false,"github":"https://github.com/Mr-Destroyer/endpointhunter","clone":"git clone https://github.com/Mr-Destroyer/endpointhunter.git","description":"EndpointHunter is a powerful bug bounty tool designed to hunt and extract API endpoints, LFI paths, secrets, and cloud storage URLs from JS, CSS, and HTML files. It's built for efficiency, supporting multi-threaded scanning and seamless integration with other popular recon tools.","language":"Python","stars":11,"topics":["api-enumeration","api-security","api-testing","bug-hunting","bugbounty","ctf-tools","endpoint-discovery","ethical-hacking","javascript","js-analysis"],"license":null,"category":"scrapers-browser-automation","readme_excerpt":"🏹 EndpointHunter EndpointHunter is a powerful bug bounty tool designed to hunt and extract API endpoints, LFI paths, secrets, and cloud storage URLs from JS, CSS, and HTML files. It's built for efficiency, supporting multi-threaded scanning and seamless integration with other popular recon tools. --- ✨ Features - 🔍 Extracts: API Endpoints (v1, graphql, rest, etc.), Query Parameters, LFI/Path Traversal vectors, Secrets (Tokens, Keys, JWT), S3 Buckets, and Internal IPs. - ⚡ Multi-threaded: Fast processing of multiple targets. - 🔗 Smart Recon: Automatically finds and scans linked JS/CSS files from a target HTML page. - 🛠️ Pipeline Friendly: Works perfectly with cat , grep , katana , gau , waybackurls , etc. - 🧹 Noise Reduction: Automatically filters out common static assets like images, fonts, and icons. --- 🚀 Installation 1. Clone the repository: 2. Install dependencies: --- 🛠️ Usage 1. Single URL Mode Scan a single target for hidden endpoints and queries: 2. Multiple URLs (File Input) Scan a list of URLs from a file: 3. Save Output Save the extracted findings to a text file: --- 🔗 Bug Bounty Workflow (Chaining Tools) EndpointHunter is designed to sit in the middle of your recon pipeline. Chaining with Katana Crawl a site and hunt for endpoints in all discovered JS files: Chaining with GAU (Get All URLs) Fetch historical URLs and pipe them to hunt for secrets: Chaining with Waybackurls --- 📜 Credit & Author Developed with ❤️ by MrDestroyer . - YouTube: @Study Hard69 - ","default_branch":null,"files":null,"tree":[],"storefront":"/r/Mr-Destroyer","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Mr-Destroyer/endpointhunter/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}