JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information in JavaScript files with surgical precision.
☆17Apr 13, 2026Updated 3 months ago
Alternatives and similar repositories for JSHawk
Users that are interested in JSHawk are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 5 months ago
- A C#-implemented malware that dynamically modifies its own hash upon each execution to evade detection.☆17Feb 3, 2025Updated last year
- Just a nice little shellcode loader using unconventional methods to avoid using signatured APIs☆23Jul 11, 2025Updated last year
- ⚡ SheetStrike - Weaponize Excel files for red team operations. Inject stealthy tracking pixels and NTLMv2 hash capture payloads into XLSX…☆22Dec 23, 2025Updated 6 months ago
- A powerful URL parameter and request fuzzing tool that processes URLs or Burp Suite raw requests, replacing values with custom payloads w…☆21Apr 12, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Man-In-The-Service tool to turn servers against their admins☆38Nov 12, 2025Updated 8 months ago
- A lexer and parser for Sleep☆21Feb 20, 2026Updated 5 months ago
- string encryption in Nim☆19Jun 15, 2024Updated 2 years ago
- Active Directory share enumeration tool☆13Apr 28, 2025Updated last year
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- Match & Replace rules for Portswigger's Burp that operate globally across all utilities.☆24Jan 26, 2026Updated 5 months ago
- Burp plugin for jxscout☆23May 12, 2025Updated last year
- Terminate AV/EDR processes by exploiting the vulnerable NsecSoft driver☆32Sep 15, 2025Updated 10 months ago
- Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.☆34Apr 14, 2026Updated 3 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- crystal palace + draugr function hook definition generator☆17Jan 27, 2026Updated 5 months ago
- An executable that simplifies adding the msds-AllowedToActOnBehalfOfOtherIdentity attribute for RBCD☆50Mar 10, 2025Updated last year
- Process Ghosting is a technique in which a process is created from a delete pending file. This means the created process is not backed by…☆16May 6, 2024Updated 2 years ago
- Enhanced Burp Suite extension for finding links and sensitive data in JavaScript files☆26May 10, 2026Updated 2 months ago
- 🐐 GoatOS - A lightweight Linux distribution focused on Web & API penetration testing. Built on Debian with GNOME, featuring nuclei, http…☆18Dec 26, 2025Updated 6 months ago
- A tool to assist DLL hijacking via the Havoc GUI☆14Jan 9, 2024Updated 2 years ago
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆28May 23, 2026Updated last month
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.☆23Nov 11, 2025Updated 8 months ago
- AI-powered malware traffic analysis and network forensics via the Model Context Protocol☆18May 27, 2026Updated last month
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Research into Undocumented Behavior of Azure AD Refresh Tokens☆13Oct 27, 2023Updated 2 years ago
- Looks for parameters in urls☆35Oct 14, 2024Updated last year
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆25Sep 29, 2023Updated 2 years ago
- Tool to transplant a valid code signature from one Portable Executable (PE) binary to another.☆16Apr 24, 2020Updated 6 years ago
- Automatically look for paramater reflections in the HTTP response☆17Apr 30, 2025Updated last year
- Monitoring tool to detect patterns or IOCs (strings, regex, VirusTotal) and alert you and your team via console, Telegram or SMS written …☆17Feb 17, 2026Updated 5 months ago
- Help red teams find opsec processes during engagements☆44Dec 7, 2024Updated last year
- A different approach to writing BOFs in rust.☆21Aug 20, 2025Updated 11 months ago
- MCP Attack Surface Detector - Burp plugin to make manual testing of MCP servers easier in Burp Suite☆30Feb 26, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a s…☆66Jul 10, 2026Updated last week
- A Payload Analysis Framework☆123Oct 9, 2025Updated 9 months ago
- 一款支持检测web应用程序未授权访问缺陷的burp suite插件,可自定义配置检测字段以及返回包json数据分析☆13Apr 22, 2024Updated 2 years ago
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- Monitors and curates bug-bounty related repositories weekly (Monday).☆20Updated this week
- ⚡ AI-powered directory listing scanner that hunts for exposed secrets and classifies security risks.☆38Sep 18, 2025Updated 10 months ago
- Threat modeling playbook for cloud-native, AI (RAG, agents), and A2A systems with STRIDE, risk models, controls, and test plans.☆18Jul 3, 2026Updated 2 weeks ago