
SwaggerSpy
Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub…

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

A tool to capture all the git secrets by leveraging multiple open source git searching tools

A tool to scan Kubernetes cluster for risky permissions

A tool to hunt for credentials in github wild AKA git*hunt

Tool to search secrets in various filetypes.

Web-based dashboard to visualize, filter, and analyze secrets discovered by TruffleHog, with batch verification, export, and session management for…

This is a mirror of a forked repository. It adds several features to gitrob including GitLab support, commit content searching, in-memory repository…

Reconnaissance tool for GitHub organizations

a Go code to detect leaks in JS files via regex patterns


「🔑」A tool used to hunt down API key leaks in JS files and pages

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…