finds.dev← search

// the find

arkadiyt/bounty-targets-data

★ 3,967 · MIT · updated Oct 2026

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

A data-only repo that dumps bug bounty program scopes from HackerOne, Bugcrowd, Intigriti, and YesWeHack into flat files and raw JSON, refreshed every 30 minutes. It's for bug bounty hunters and recon tooling authors who want a single feed of in-scope domains instead of hitting each platform's API themselves.

Solves a real, narrow problem well: four platforms' scope data normalized into domains.txt and wildcards.txt that you can pipe straight into subdomain enumeration or recon scripts. The update cadence (30 min, last change 3967 commits deep) means it's actually fresh, not a stale one-time export. Raw per-platform JSON is kept alongside the normalized lists, so you can go back to source fields if the flattened format drops something you need.

There's no code in this repo at all — the actual scraper lives in a separate bounty-targets repo, so if you want to understand how domains.txt is generated or file a bug about a parsing issue, you're immediately redirected elsewhere. No schema documentation for the JSON files, so you're reverse-engineering field names from each platform's own quirks. The README's own caveat about wildcards.txt (a wildcard can be in-scope while a subdomain of it is explicitly excluded) means you can't use the files as a submit-blindly list — you still have to go cross-check each program's actual rules, which undercuts the main pitch of a ready-to-use scope feed. Federacy and Hackenproof are commented out as dead platforms with no note on when or why they were dropped.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →