
eviltree
A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

Find, verify, and analyze leaked credentials

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Finding secrets in kernel and user memory

a guard that blocks catastrophic agent actions

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Extracts secrets (passwords, API keys, tokens) from WARC web archives using Gitleaks rules. Supports HTTP, S3, local files, and compressed archives…

BeHat Configuration file leaking

Appspec YML and YAML leaks

Go scripts for finding sensitive data like API key / some keywords in the github repository

Cloud native secrets management for developers - never leave your command line for secrets.

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

Analyze any GitHub repo (URL or local path) → architecture map, verified run commands, risks, and actionable issues - in minutes.

Parse and visualize /proc/self/environ on compromised Linux boxes — categorizes env vars by tech stack (AWS, Django, Rails, NodeJS, MySQL, K8s,…