
AWS-Key-Hunter
[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Check UNIX/Linux systems for privilege escalation

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Automated web security auditing tool that detects environment misconfigurations, probes backend vulnerabilities, and bypasses WAF/IDS protections…

VisualCodeGrepper - Code security scanning tool.

Automated Kubernetes cluster penetration testing tool that exploits misconfigurations in API, Kubelet, etcd, and Dashboard to achieve node takeover…

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

🔥 A powerful MongoDB auditing and pentesting tool 🔥

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.

Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.

Bucky (An automatic S3 bucket discovery tool)

Multi-threaded Go tool to detect nginx alias traversal vulnerabilities using heuristic and brute-force techniques for identifying vulnerable…

A simple CORS misconfiguration scanner

Cross Origin Resource Sharing MisConfiguration Scanner

Scanner for CVE-2024-40725 Apache HTTP Server source-code disclosure; probes direct and subrequest paths, fingerprints affected versions, and outputs…

A specialized vulnerability scanner designed to detect CVE-2024-38526, the Polyfill.io Supply Chain Attack, helping organizations identify and…