
sast-scan
Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

Open source compliance tool for development platforms.

A simple file-based scanner to look for potential AWS access and secret keys in files

Hunt for AI coding artifacts containing secrets.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Mobile app security auditing tool focused on automating SAST analysis, identifying underlying technologies (React Native, Flutter, Xamarin, native),…

Cloud native secrets management for developers - never leave your command line for secrets.

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

find hardcoded strings from source code

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…