
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

A static analysis security vulnerability scanner for Ruby on Rails applications

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Read-only scanner for what lets a repository run code in a coding agent (Claude Code, Codex, Cursor, Copilot): git settings, hooks, and committed MCP…

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

An extension for checking if .git is exposed in visited websites

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

CVE-2025-46811

Windows Remote Desktop Services Vulnerability Allows Remote Code Execution

Global API Integrity Assessor

Python-based exploit for CVE-2024-4577 PHP argument injection vulnerability with single-target and batch scanning capabilities.