JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information in JavaScript files with surgical precision.
☆17Apr 13, 2026Updated 3 months ago
Alternatives and similar repositories for JSHawk
Users that are interested in JSHawk are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 5 months ago
- A C#-implemented malware that dynamically modifies its own hash upon each execution to evade detection.☆17Feb 3, 2025Updated last year
- Just a nice little shellcode loader using unconventional methods to avoid using signatured APIs☆23Jul 11, 2025Updated last year
- ⚡ SheetStrike - Weaponize Excel files for red team operations. Inject stealthy tracking pixels and NTLMv2 hash capture payloads into XLSX…☆22Dec 23, 2025Updated 7 months ago
- A powerful URL parameter and request fuzzing tool that processes URLs or Burp Suite raw requests, replacing values with custom payloads w…☆21Apr 12, 2026Updated 3 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Man-In-The-Service tool to turn servers against their admins☆38Nov 12, 2025Updated 8 months ago
- A lexer and parser for Sleep☆21Feb 20, 2026Updated 5 months ago
- string encryption in Nim☆19Jun 15, 2024Updated 2 years ago
- Active Directory share enumeration tool☆13Apr 28, 2025Updated last year
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- Burp plugin for jxscout☆23May 12, 2025Updated last year
- Match & Replace rules for Portswigger's Burp that operate globally across all utilities.☆24Jan 26, 2026Updated 6 months ago
- Terminate AV/EDR processes by exploiting the vulnerable NsecSoft driver☆32Sep 15, 2025Updated 10 months ago
- Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.☆33Apr 14, 2026Updated 3 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- crystal palace + draugr function hook definition generator☆17Jan 27, 2026Updated 6 months ago
- An executable that simplifies adding the msds-AllowedToActOnBehalfOfOtherIdentity attribute for RBCD☆50Mar 10, 2025Updated last year
- Process Ghosting is a technique in which a process is created from a delete pending file. This means the created process is not backed by…☆16May 6, 2024Updated 2 years ago
- 🐐 GoatOS - A lightweight Linux distribution focused on Web & API penetration testing. Built on Debian with GNOME, featuring nuclei, http…☆18Dec 26, 2025Updated 7 months ago
- Enhanced Burp Suite extension for finding links and sensitive data in JavaScript files☆26May 10, 2026Updated 2 months ago
- A tool to assist DLL hijacking via the Havoc GUI☆14Jan 9, 2024Updated 2 years ago
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 8 months ago
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆28May 23, 2026Updated 2 months ago
- AI-powered malware traffic analysis and network forensics via the Model Context Protocol☆18May 27, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Research into Undocumented Behavior of Azure AD Refresh Tokens☆13Oct 27, 2023Updated 2 years ago
- Looks for parameters in urls☆35Oct 14, 2024Updated last year
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆25Sep 29, 2023Updated 2 years ago
- Tool to transplant a valid code signature from one Portable Executable (PE) binary to another.☆16Apr 24, 2020Updated 6 years ago
- Automatically look for paramater reflections in the HTTP response☆17Apr 30, 2025Updated last year
- Monitoring tool to detect patterns or IOCs (strings, regex, VirusTotal) and alert you and your team via console, Telegram or SMS written …☆17Feb 17, 2026Updated 5 months ago
- Help red teams find opsec processes during engagements☆45Dec 7, 2024Updated last year
- A different approach to writing BOFs in rust.☆21Aug 20, 2025Updated 11 months ago
- AI Substitutor is an extension for Burp Suite that uses AI functionality to substitute values of HTTP request parameters and headers.☆29Apr 30, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- MCP Attack Surface Detector - Burp plugin to make manual testing of MCP servers easier in Burp Suite☆31Feb 26, 2026Updated 5 months ago
- Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a s…☆67Jul 10, 2026Updated 3 weeks ago
- A Payload Analysis Framework☆122Oct 9, 2025Updated 10 months ago
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- Monitors and curates bug-bounty related repositories weekly (Monday).☆62Aug 3, 2026Updated last week
- 一款支持检测web应用程序未授权访问缺陷的burp suite插件,可自定义配置检测字段以及返回包json数据分析☆13Apr 22, 2024Updated 2 years ago
- ☆21Dec 29, 2024Updated last year