
dnsReaper
Fast subdomain takeover scanner with 50+ signatures, supporting cloud provider integrations (AWS, Azure, Cloudflare) and CI/CD pipeline mode for…

Fast subdomain takeover scanner with 50+ signatures, supporting cloud provider integrations (AWS, Azure, Cloudflare) and CI/CD pipeline mode for…

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

An active monitoring software to detect failures before your customers do.

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production

GitHub Actions Pipeline Enumeration and Attack Tool

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.


OWASP Domain Protect - prevent subdomain takeover

Like Envoy xDS, but for eBPF filters

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform

A fast port scanner written in go with a focus on reliability and simplicity.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Collection of quality safety articles. Awesome articles.