
SwaggerSpy
Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

Passive recon & attack surface mapper — zero requests sent

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…