
aura-inspector
Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Check UNIX/Linux systems for privilege escalation

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

🔥 A powerful MongoDB auditing and pentesting tool 🔥

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.

Scanner for CVE-2024-40725 Apache HTTP Server source-code disclosure; probes direct and subrequest paths, fingerprints affected versions, and outputs…

TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.

Bucky (An automatic S3 bucket discovery tool)

Multi-threaded Go tool to detect nginx alias traversal vulnerabilities using heuristic and brute-force techniques for identifying vulnerable…

A simple CORS misconfiguration scanner

Cross Origin Resource Sharing MisConfiguration Scanner

A specialized vulnerability scanner designed to detect CVE-2024-38526, the Polyfill.io Supply Chain Attack, helping organizations identify and…

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]

Python-based scanner that detects debug mode misconfigurations in web applications using multiple HTTP methods and fingerprinting techniques to…

VisualCodeGrepper - Code security scanning tool.

Automated Kubernetes cluster penetration testing tool that exploits misconfigurations in API, Kubelet, etcd, and Dashboard to achieve node takeover…