
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Proof-of-concept exploit for CVE-2024-52510 demonstrating signature bypass in Nextcloud's E2EEv2 protocol, enabling server-side decryption of…

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Security Tool to Look For Interesting Files in S3 Buckets

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Simple and flexible tool for managing secrets

A list of awesome penetration testing tools and resources.

Rust library and format specification for creating and loading Independent Guest Virtual Machine (IGVM) files, supporting hardware-isolated VMs with…

Verdict-as-a-Service SDKs: Analyze files for malicious content

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

The source files and tools needed to build the OWASP Cornucopia decks in various languages

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

Secure, ephemeral secret sharing for developers.

Audit and educational toolkit for CVE-2026-5006, a Vault templated-policy slash-injection vulnerability. Includes a read-only audit script generating…