
GitHacker
🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

🧬 Extract and analyze contributors info from git repos

A tool to dump a git repository from a website

PoC: identify silent security patches before CVE

This is the home of the Expel Intel Team. Here, we will share IOCs and other information that is either not suitable for fitting into other mediums…

An extension for checking if .git is exposed in visited websites

A pentesting tool that dumps the source code from .git even when the directory traversal is disabled

Single-script exploit for CVE-2026-44881 that chains .git credential leakage, Portainer Git-symlink injection, arbitrary host file read, and SSH…

This tool is designed to scan and identify whether a website has an exposed ".git" directory, which may contain sensitive information such as source…

This script is a tool to recursively download the contents of the '.git' directory from a website. Using Python and libraries like 'requests' and…

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

Active Directory information dumper via LDAP

Exploit for CVE-2017-5487 to enumerate WordPress user accounts via the REST API, extracting sensitive information from vulnerable 4.7 installations.

🖇 Enumerate git repository URL from list of URL / User / Org. Friendly to pipeline

Unauthenticated SQL injection exploit for WordPress versions 2.1.3 to 2.8.2, targeting the Ultimate Member plugin to extract sensitive database…

CVE-2023-23752 Data Extractor