controlplaneio / truffleproc
truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)
☆114Updated last year
Alternatives and similar repositories for truffleproc:
Users that are interested in truffleproc are comparing it to the libraries listed below
- boostsecurityio/lotp☆116Updated last week
- ☆110Updated last year
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆132Updated last week
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆102Updated last month
- Tools to assess DNS security.☆151Updated last year
- ☆68Updated 2 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆40Updated last year
- ☆175Updated 4 months ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆138Updated 3 years ago
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆216Updated last week
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where w…☆104Updated 4 months ago
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆53Updated last month
- Protect against subdomain takeover☆93Updated 10 months ago
- This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits containing potential secret or interesting…☆46Updated 7 months ago
- Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently …☆273Updated last month
- ☆164Updated 6 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆61Updated last year
- Cloud agnostic IAM permissions enumerator☆140Updated 6 months ago
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated last year
- Semgrep-based Policy Controller for Kubernetes☆47Updated last week
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆81Updated last year
- HASH (HTTP Agnostic Software Honeypot)☆137Updated 10 months ago
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆39Updated 3 months ago
- ☆45Updated 9 months ago
- Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments☆138Updated 2 months ago
- A tool to uncover undocumented APIs from the AWS Console.☆99Updated 4 months ago
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆200Updated 2 months ago
- ☆58Updated last year
- A research project to add some brrrrrr to Burp☆139Updated last month
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆83Updated 2 weeks ago