
AzureAttackKit
Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Find credentials in screenshots, save them to your secret manager, and irreversibly redact them from the image — local, offline, OCR-based.

Passive recon & attack surface mapper — zero requests sent

Pillage filesystems for sensitive information with Go 🔍

Prevents you from committing secrets and credentials into git repositories

Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.

a recon tool that finds sensitive data inside the screenshots uploaded to prnt.sc

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

Extracts secrets (passwords, API keys, tokens) from WARC web archives using Gitleaks rules. Supports HTTP, S3, local files, and compressed archives…

Extract URLs, paths, secrets, and other interesting bits from JavaScript

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

Jbin will gather all the URLs from the website and then it will try to expose the secret data from them such as API keys, API secrets, API tokens and…

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).