
HTTPLoot
An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

a recon tool that finds sensitive data inside the screenshots uploaded to prnt.sc

Slack enumeration and exposed secrets detection tool

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…

The simple PoC of CVE-2023-27587

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

A static analysis tool for securing Go code

Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536,…