
Llama-Stack-0.4.0rc3-local-CVE-2026-25211
Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

This Repositories contains list of One Liners with Descriptions and Installation requirements

Hunting for passwords with deep learning

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

A collection oneliner scripts for bug bounty

List of regex for scraping secret API keys and juicy information.

A tool for pointesters to find candies in SharePoint

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Useful Google Dorks for WebSecurity and Bug Bounty

Slack enumeration and exposed secrets detection tool

Notes about attacking Jenkins servers

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Burp Plugin for Secret Matching

Appspec YML and YAML leaks

BeHat Configuration file leaking