Github Search is a quite powerful and useful feature that can be used to search for sensitive data on repositories. Collection of Github dorks can reveal sensitive personal and/or organizational information such as private keys, credentials, authentication tokens, etc.This list is supposed to be useful performing pen-testing of systems.
☆21Aug 11, 2024Updated 2 years ago
Alternatives and similar repositories for github-recon
Users that are interested in github-recon are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- فایل ها و فیلم های ورکشاپ ردتیم 2024 با هانت لرن☆33Sep 15, 2024Updated last year
- ☆28Feb 10, 2026Updated 6 months ago
- 一个用于修改右键插件菜单层级的Burpsuite插件。A simple BurpSuite extension to change extension context menu level.☆14Jan 15, 2024Updated 2 years ago
- A proof of concept program that pulls and parses security.txt files at mass.☆30May 31, 2023Updated 3 years ago
- The tool that bypasses the firewall's Application Based Rules and lets you connect to anywhere, ANY IP, ANY PORT and ANY APPLICATION.☆62Aug 19, 2024Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Raven is a powerful and customizable web crawler written in Go.☆40Sep 3, 2024Updated last year
- Web Penetration Testing Course Materials☆30May 13, 2024Updated 2 years ago
- KakHunt is a python GUI Tool private tool which earns me 100s of bugs every month. It spawns URLS and filters Sensitive Info.☆50Apr 27, 2023Updated 3 years ago
- XSS scanning with Dalfox on Github-action☆26Nov 26, 2023Updated 2 years ago
- Encode or decode base64 or base32 using a custom alphabet☆12Jan 29, 2019Updated 7 years ago
- Some files for bruteforcing certain things.☆28Jul 12, 2021Updated 5 years ago
- ☆14Dec 21, 2023Updated 2 years ago
- ☆64Aug 22, 2024Updated 2 years ago
- Run ffuf with the appropriate options to brute-force the directories using the awesome different wordlists.☆25Apr 19, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Exploit for CVE-2024-20767 - Adobe ColdFusion☆34Dec 19, 2024Updated last year
- Nuclei POC 模板☆10Feb 17, 2023Updated 3 years ago
- Amassing wealth in the form of biochemical tactical nuclear hack precision strike notes for existential fulfillment and destruction of th…☆14Feb 19, 2022Updated 4 years ago
- Unauthorized Docker Exploitation Tool☆37Dec 24, 2023Updated 2 years ago
- Python tool for detecting subdomain takeover vulnerabilities by resolving CNAME records and checking for known error messages. It support…☆14Feb 2, 2025Updated last year
- header-fuzz allows you to fuzz any HTTP header with a wordlist and evaluate success or failure based on the returning HTTP status code.☆16Apr 15, 2020Updated 6 years ago
- A simple browser extension to quickly find interesting security-related information on a webpage.☆188Updated this week
- 蜜罐检测工具,支持自动化URL去重、多线程控制及智能速率限制。可识别伪装服务。☆16Jun 5, 2025Updated last year
- This tool live-monitors specified Telegram channels for messages that contain certain keywords and forwards them to a private channel.☆39Oct 14, 2024Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A cheatsheet of tools and commands that I use to pentest Active Directory.☆55Mar 26, 2022Updated 4 years ago
- The OWASP Testing Guide v4.2 Checlist [2023]☆13Jan 15, 2023Updated 3 years ago
- CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds☆21May 15, 2024Updated 2 years ago
- Reversing Citrix Gateway for XSS☆17Jul 3, 2023Updated 3 years ago
- ☆10Jun 10, 2023Updated 3 years ago
- An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails c…☆166Oct 9, 2024Updated last year
- This script checks the status of URLs to see if they are alive or not.☆13Nov 22, 2024Updated last year
- Dump Kerberos tickets from the KCM database of SSSD☆59Dec 31, 2025Updated 8 months ago
- A tool which helps identifying client-side prototype polluting libraries☆40May 1, 2025Updated last year
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- MetaX - Advanced XSS Vulnerability Detector☆15Dec 30, 2025Updated 8 months ago
- Find The Admin Panel & SQL Injection Endpoints, Using Google Dorks !!!☆31Nov 15, 2024Updated last year
- Patches the AmsiScan function in clr.dll allowing for unrestricted assembly loading in .NET☆53May 5, 2025Updated last year
- using ML models for red teaming☆43Aug 9, 2023Updated 3 years ago
- Mutation-driven HTTP fuzzing for Burp Suite☆15Mar 2, 2026Updated 5 months ago
- Exploits with pwntools library in Python3. ROP, BOF, SHELLCODE.☆20Feb 2, 2024Updated 2 years ago
- ☆41May 1, 2026Updated 3 months ago