
Google-api-key-scanner
Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.

Supermicro IPMI/BMC Cleartext Password Scanner

Pentester-focused Docker registry tool to enumerate and pull images

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

The format of various s3 buckets is convert in one format. for bugbounty and security testing.

Suite of programs meant to aid in bug hunting and security assessments

Retrieve AD accounts description and search for password in it


ActionScript Proof of Concept to perform cross-domain reads

泛微ecology OA系统接口存在数据库配置信息泄露漏洞

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

FAST WEB APPLICATION VULNERABILITY SCANNER written in python3

find sensitive data leaking from ServiceNow instances.

DNSint - A comprehensive DNS reconnaissance and OSINT toolkit for domain intelligence gathering and security analysis.

Detect security issues in an Apache CouchDB server

Mounts AWS resources as a local filesystem for infrastructure exploration, security auditing, and configuration analysis using standard Unix tools…