
awesome-devsecops
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Useful Google Dorks for WebSecurity and Bug Bounty

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

how to look for Leaked Credentials !

Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

This Repositories contains list of One Liners with Descriptions and Installation requirements

Python source code auditing and static analysis on a large scale

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.


A collection oneliner scripts for bug bounty

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Passive LLM Conversation Capture & Sensitive Data Exposure Research

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only