


Reconnaissance tool for GitHub organizations

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Find leaked secrets via github search

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github,…

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Tool for advanced mining for content on Github

Notes about attacking Jenkins servers

Extract URLs, paths, secrets, and other interesting bits from JavaScript

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

A collection of tools to perform searches on GitHub.

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…
