
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom…

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…

Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple…

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

automated web assets enumeration & scanning [DEPRECATED]

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Incredibly fast crawler designed for OSINT.

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

A wrapper around grep, to help you grep for things

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and…