
ThreatMapper
Open Source Cloud Native Application Protection Platform (CNAPP)

Open Source Cloud Native Application Protection Platform (CNAPP)

A utility for detecting webpage inputs and conducting XSS scans.

「🔑」A tool used to hunt down API key leaks in JS files and pages

Proof-of-Concept scanner for CVE-2025-68645, detecting Local File Inclusion (LFI) in Zimbra Collaboration Suite via the /h/printcalendar endpoint…

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

CVE-2022-37122 Path Traversal Scanner

Nuclei-based toolkit for detecting and validating the FreePBX authentication bypass vulnerability (CVE-2025-57819) with detection and exploit PoC…

Next.js CVE-2025-29927 Hunter

Nuclei template for CVE-2025-30208, exploiting a file read vulnerability in Vite. Includes search queries for Hunter, FOFA, and Shodan to identify…

Hunt for security weaknesses in Kubernetes clusters

The Binarly Firmware Hunt (FwHunt) rule format was designed to scan for known vulnerabilities in UEFI firmware.

CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.

A basic phishing kit scanner for dedicated and semi-dedicated hosting

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

A Shodan hunter for CVE-2022-40140

Automated bulk IP or domain scanner for CVE 2020 3580. Cisco ASA and FTD XSS hunter.