brosck / mantra
ćšćA tool used to hunt down API key leaks in JS files and pages
ā625Updated last month
Alternatives and similar repositories for mantra:
Users that are interested in mantra are comparing it to the libraries listed below
- jsleak is a tool to find secret , paths or links in the source code during the recon.ā505Updated this week
- SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bountyā497Updated last month
- Fast and customizable subdomain wordlist generator using DSLā762Updated this week
- A Powerful Sensor Tool to discover login panels, and POST Form SQLi Scanningā477Updated last year
- An IIS short filename enumeration toolā860Updated 2 months ago
- Tool to bypass 403/40X response codes.ā1,169Updated 3 weeks ago
- Simple tool to scan a website for (DOM-based) XSS vulnerabilities and Open Redirects.ā232Updated this week
- Find subdomains with GPT, for freeā337Updated 9 months ago
- A simple tool for bypassing file upload restrictions.ā811Updated 6 months ago
- ā519Updated 7 months ago
- HTTP 403 bypass toolā480Updated 10 months ago
- User-Agent , X-Forwarded-For and Referer SQLI Fuzzerā381Updated last year
- A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a ā¦ā581Updated this week
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.ā56Updated 8 months ago
- ā519Updated 7 months ago
- LFI-FINDER is an open-source tool available on GitHub that focuses on detecting Local File Inclusion (LFI) vulnerabilitiesā295Updated last year
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.ā573Updated 2 months ago
- A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflowsā277Updated last year
- NucleiFuzzer is a robust automation tool designed for efficiently detecting web application vulnerabilities, including XSS, SQLi, SSRF, aā¦ā1,412Updated this week
- i will upload more templates here to share with the comunity.ā541Updated 9 months ago
- A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.ā493Updated this week
- how to look for Leaked Credentials !ā773Updated 8 months ago
- An extremely effective subdomain enumeration wordlist of 3,000,000 lines, crafted by harvesting SSL certs from the entire IPv4 space.ā580Updated last year
- Golang client for querying SecurityTrails API dataā545Updated last year
- Automated Tool for Testing Header Based Blind SQL Injectionā268Updated last year
- oneliner commands for bug bountiesā433Updated 2 years ago
- My Priv8 Nuclei Templatesā297Updated 8 months ago
- AllForOne allows bug bounty hunters and security researchers to collect all Nuclei YAML templates from various public repositories,ā574Updated 10 months ago
- The most powerful CRLF injection (HTTP Response Splitting) scanner.ā567Updated last year
- A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas iā¦ā169Updated 4 months ago