
gf
A wrapper around grep, to help you grep for things

A wrapper around grep, to help you grep for things

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

Main repo for hosting release binaries

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Mind-Maps of Several Things

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Shell scripts to clone and mirror Git repositories, compute deltas, and run gitleaks to detect secrets hidden in deleted or reset commits.

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

NCC Code Navigator

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Tool to search secrets in various filetypes.

AI-powered assistant for penetration testers that generates payloads, analyzes code, performs reconnaissance, and executes command-line actions to…

Go scripts for finding sensitive data like API key / some keywords in the github repository

🧬 Extract and analyze contributors info from git repos