
gimmepatz
Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Python-based scanner that detects debug mode misconfigurations in web applications using multiple HTTP methods and fingerprinting techniques to…

CLI tool to detect and update BCrypt password hashes with vulnerable work factor 31, integrating with Spring Security databases for CVE-2022-xxxx…

:owl::mag_right: A simple tool to audit your AWS/GCP infrastructure for misconfiguration or potential security issues with plugins integration

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

Test tool for CVE-2024-26144 that checks if web servers and CDNs improperly cache HTTP responses containing Set-Cookie headers, revealing cache…

This tool is used to find php info page

Scan publicly accessible assets on your AWS cloud environment

Shell script and Ansible playbook to detect and remediate CVE-2024-3094 in xz-utils by checking package versions, upgrading or downgrading to a…

a plugin that protects your wp site from the CVE-2017-8295 vulnerability

A tool to scan Kubernetes cluster for risky permissions

Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

A tool to hunt for publicly accessible DigitalOcean Spaces

The only open-source tool to analyze vulnerabilities and configuration issues with running docker container(s) and docker networks.

Multi-threaded Go tool to detect nginx alias traversal vulnerabilities using heuristic and brute-force techniques for identifying vulnerable…

Pentester-focused Docker registry tool to enumerate and pull images