
dufflebag
Search exposed EBS volumes for secrets

Search exposed EBS volumes for secrets

Harden your package manager configs against supply chain attacks.

You can read the writeup on this script here

Python source code auditing and static analysis on a large scale

Slack enumeration and exposed secrets detection tool

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Pillage filesystems for sensitive information with Go 🔍

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Find and redact secrets in AI coding agent histories (Claude Code, and more).

Finding exposed secrets and personal data in GitLab

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

Deploy a FullStack Prodo-Typing Agent into your AWS Account (KiroCrew,OpenClaw, Hermes, Claude Code, Codex)

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Scans public GitHub repositories for accidentally uploaded sensitive data like credentials, secret keys, and tokens using a personal access token.

Powerful protection for AI agents - Open-source security and cost tracking for AI applications

Regex-based scanner for detecting hard-coded credentials in codebases, designed for CI/CD integration with suppression comment support and low…