
SubDomainizer
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing


Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more


Find credentials in screenshots, save them to your secret manager, and irreversibly redact them from the image — local, offline, OCR-based.


Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Passive recon & attack surface mapper — zero requests sent

Slack enumeration and exposed secrets detection tool

GitHub Actions Pipeline Enumeration and Attack Tool

🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github,…

「🔑」A tool used to hunt down API key leaks in JS files and pages