
mantra
「🔑」A tool used to hunt down API key leaks in JS files and pages

「🔑」A tool used to hunt down API key leaks in JS files and pages

a recon tool that finds sensitive data inside the screenshots uploaded to prnt.sc

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Slack enumeration and exposed secrets detection tool

Validates leaked API tokens and keys using customizable JSON-based signature checks. Designed for pentesters and bug hunters to determine the impact…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.

Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

Search exposed EBS volumes for secrets

You can read the writeup on this script here

A tool to hunt for credentials in github wild AKA git*hunt

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

Hunting for passwords with deep learning

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

A tool for pointesters to find candies in SharePoint