
stretcher
Tool designed to help identify open Elasticsearch servers that are exposing sensitive information

Tool designed to help identify open Elasticsearch servers that are exposing sensitive information

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046

A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)

Automated SPF and DMARC configuration checker that identifies email spoofing vulnerabilities across single or bulk domains using DNS lookups.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

PAVELOW Exploit Toolbox is a BASH script that corresponds with your KALI distro to better help your vulnerability hunting and exploiting proccess…

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Async HTTP(S) scanner that greps response bodies and headers for strings or regex across hosts, ports, CIDR/ranges and TLS-cert vhosts.

Web application that lets you test if your domain is vulnerable to email spoofing

A scanner that files with compromised or untrusted code signing certificates written in python.

Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scanning — applied…

An Exploitation tool to exploit the confluence server that are vulnerable to CVE-2023-22518 Improper Authorization

OSINT tool to search, parse and dump only the open Elasticsearch and MongoDB directories that have the data you care about exposing

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…