


Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Open Source Vulnerability Management Platform

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Automagically reverse-engineer REST APIs via capturing traffic

List of API's for gathering information about phone numbers, addresses, domains etc

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.


Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

List of regex for scraping secret API keys and juicy information.

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

An easy-to-use and lightweight API wrapper for Censys APIs.

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…



A python3 script searching for secret on swaggerhub