
SubDomainizer
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

Slack enumeration and exposed secrets detection tool

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Passive recon & attack surface mapper — zero requests sent

GitHub Actions Pipeline Enumeration and Attack Tool

🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Real-time GitHub monitoring tool that searches for exposed API keys, tokens, and credentials across multiple services using regex-based detection…

「🔑」A tool used to hunt down API key leaks in JS files and pages

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

Hunt for AI coding artifacts containing secrets.

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.