
awesome-devsecops
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

This Repositories contains list of One Liners with Descriptions and Installation requirements

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

The Most Comprehensive Docker Security Scanner

List of regex for scraping secret API keys and juicy information.

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Powerful protection for AI agents - Open-source security and cost tracking for AI applications

On-prem API gateway for AI coding agents with per-engineer cost attribution, hard budgets, egress governance (secrets/entity scanning), context-rot…

A lightweight mcp to prevent poisoning CVE (CVE-2025-54136), researchers hijacking Claude Code/Copilot/Gemini via prompt injection, and hundreds of…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…