Matchboxmatchbox
← Back to match

Garud

Automation script that chains recon tools to find subdomain takeovers and bugs.

Desktopfree

Garud is an open-source bug bounty automation tool that runs a full subdomain-recon and vulnerability-triage pipeline in one command, chaining tools like subfinder, amass, nuclei, and dalfox to surface subdomain takeovers and XSS/SSTI/SSRF injection points. Built for bug bounty hunters who want to automate repetitive recon instead of running each tool manually.

Categories
SecurityReconnaissanceBug Bounty

Full match profile

Behind the summary, Matchbox keeps a richer profile of Garud - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether Garud (or something else) actually fits.