
AWSBucketDump
Security Tool to Look For Interesting Files in S3 Buckets

Security Tool to Look For Interesting Files in S3 Buckets

uDork is a script written in Bash Scripting that uses advanced Google search techniques to obtain sensitive information in files or directories, find…

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…

Exploit for Grafana LFI vulnerability CVE-2021-43798 enabling unauthorized file reading via path traversal in plugin endpoints.

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

A python script that finds endpoints in JavaScript files

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…

A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in…

Just basic scanner abusing CVE-2020-3452 to enumerate the standard files accessible in the Web Directory of the CISCO ASA applicances.

Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files.

a Go code to detect leaks in JS files via regex patterns

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Fetches JavaScript files quickly and comprehensively.

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Scraping tool to ennumerate directories or files with the CVE-2024-23897 vulnerability in Jenkins.

Collects files and commands post-exploitation, formats them into Markdown reports, and helps find sensitive information for red team reporting.