
gimmepatz
Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

Private key usage verification

OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub…

Identify hardcoded secrets in static structured text

A tool for secrets management, encryption as a service, and privileged access management

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Passive recon & attack surface mapper — zero requests sent

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

A tool to scan Kubernetes cluster for risky permissions

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

A tool to capture all the git secrets by leveraging multiple open source git searching tools

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Pluggable linting tool to prevent committing credential.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

A tool to hunt for credentials in github wild AKA git*hunt

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files