
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Find, verify, and analyze leaked credentials

AI-powered bug bounty hunting toolkit that works with or without subscription.

A library for detecting known secrets across many web frameworks

Enumerates AWS environments for secrets by scanning EC2 userdata, Lambda environment variables and source code, and CodeBuild instances for…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…

The simple PoC of CVE-2023-27587

Shell scripts to clone and mirror Git repositories, compute deltas, and run gitleaks to detect secrets hidden in deleted or reset commits.

Scans Docker Hub images using regex patterns to extract exposed secrets, private keys, and authentication tokens for security auditing and incident…

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

automated web assets enumeration & scanning [DEPRECATED]

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

Tool for advanced mining for content on Github

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

A wrapper around grep, to help you grep for things