
GraphStrike
Cobalt Strike HTTPS beaconing over Microsoft Graph API

Cobalt Strike HTTPS beaconing over Microsoft Graph API

List of regex for scraping secret API keys and juicy information.

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

Proof-of-concept exploit for CVE-2018-1002105 targeting Kubernetes API server. Supports authenticated and unauthenticated privilege escalation to…

Vulnerability scanner based on vulners.com audit API

Read-only AWS service enumerator with 600+ API calls for cloud reconnaissance, info dumping, and result analysis during penetration testing.

End to End testing of Web, API, Cloud, Events and Security

Defensive research tool that documents observable API endpoints and user agents of offensive tooling targeting Microsoft Entra ID, supporting…

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Scalable API key server for issuing, verifying, and revoking credentials with token derivation for fine-grained capability tokens. Supports…

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

CLI tool for the Horizon3.ai API