
super-secret-finder
Automated secret matching plugin for Burp Suite that detects exposed API keys, tokens, and credentials in HTTP requests and responses for security…

Automated secret matching plugin for Burp Suite that detects exposed API keys, tokens, and credentials in HTTP requests and responses for security…

You can read the writeup on this script here

Scans websites and JS files for exposed Gemini API keys, verifies them live, enumerates accessible services, and provides a browser client for direct…

Enumerates AWS environments for secrets by scanning EC2 userdata, Lambda environment variables and source code, and CodeBuild instances for…

Scans web applications for React Server Actions source code exposure, extracting and detecting hardcoded secrets, API keys, and credentials.

List of regex for scraping secret API keys and juicy information.

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

Scans web applications for exposed AWS AppSpec YAML files containing sensitive data like API keys and secrets, aiding bug bounty hunters and…

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform

Exploit Jenkins instances via CVE-specific PoCs: RCE through Groovy scripts and deserialization, dump builds for cleartext secrets, password…

Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

Proof-of-concept exploit for CVE-2023-27587, demonstrating Google Cloud API key leakage via error messages in a Rust web application. Includes…

Automated vulnerability scanner that detects exposed BeHat configuration files and sends Telegram notifications. Ideal for bug bounty hunters and…

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

Jbin will gather all the URLs from the website and then it will try to expose the secret data from them such as API keys, API secrets, API tokens and…

automated web assets enumeration & scanning [DEPRECATED]

Regex-based scanner that discovers API keys, tokens, JWTs, and other secrets in JavaScript files, with support for URL extraction, custom regex, and…

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.