OWASP Hunting
OWASP Hunting — Security Testing Reference

Security Testing
Resources & Payloads

A comprehensive collection of security testing resources and payloads for authorized penetration testing, bug bounty research, and security education. Documentation for the OWASP Hunting project.

Browse DocumentationExplore PayloadsView on GitHub

Vulnerability Categories

32 payload classes organized by attack category

Injection

Access Control

Authentication & Authorization

Server-Side

Configuration & Design

Network & Anonymity

What’s inside

Payload Reference

Organized payload collections across 30+ vulnerability classes, with testing context and methodology.

Methodology Guides

Testing methodology, tooling guidance, and structured approaches to web application security.

Technical Depth

Attack vectors, indicators, detection guidance, and mitigation strategies for each vulnerability.

Fast Search

Search across payloads, documentation, and methodology with keyboard-first navigation.

Open Source

Contributing is encouraged. Content lives in the upstream OWASP Hunting repository.

Ethical Focus

All content oriented toward authorized testing, responsible disclosure, and defense.

Source Repositories

This documentation covers the OWASP Hunting project. Payloads and content originate from the upstream repository.

Upstream RepositoryOWASP

Canonical OWASP project

Development ForkFork

Active development and contributions

Who this is for

  • Penetration testers conducting authorized assessments
  • Bug bounty hunters working in-scope programs
  • Security engineers building defensive tooling
  • Students learning web application security
  • Researchers studying vulnerability classes
  • Open-source security contributors

Responsible Use

All content is intended for authorized testing only. Use these resources responsibly.

  • Systems you own or have explicit written permission to test
  • Authorized bug bounty programs with defined scope
  • Educational labs and controlled environments