FestIn - Credentialless discovery and monitoring of exposed S3-compatible cloud storage from domains, DNS and web crawling.
β233Sep 8, 2026Updated 2 weeks ago
Alternatives and similar repositories for festin
Users that are interested in festin are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Simple python script to check against hypothetical JWT vulnerability.β51Nov 29, 2020Updated 5 years ago
- Find cloud assets that no one wants exposed π βοΈβ351Jul 20, 2020Updated 6 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.β77Mar 4, 2022Updated 4 years ago
- Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.β102Jul 26, 2020Updated 6 years ago
- Suite of programs meant to aid in bug hunting and security assessmentsβ77Dec 29, 2019Updated 6 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits β’ AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Searching for virtual hosts among non-resolvable domainsβ89Apr 29, 2020Updated 6 years ago
- Search exposed EBS volumes for secretsβ305Apr 24, 2023Updated 3 years ago
- Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to β¦β758Sep 23, 2024Updated 2 years ago
- Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.β134Jul 11, 2021Updated 5 years ago
- Smart ssrf scanner using different methods like parameter brute forcing in post and get...β275Feb 11, 2021Updated 5 years ago
- Takeover subdomains using AWS dangling elastic ips and have a working POC for Subdomain Takeover.β94Jul 9, 2025Updated last year
- Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated filesβ¦β687Jul 15, 2024Updated 2 years ago
- Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.β653Nov 21, 2019Updated 6 years ago
- take a list of resolved subdomains and output any corresponding CNAMES en masse.β18Jan 29, 2026Updated 7 months ago
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- automated web assets enumeration & scanning [DEPRECATED]β288Mar 7, 2023Updated 3 years ago
- WRecon, is a tool for the recognition of vulnerabilities and blackbox information for wordpress.β24Jun 5, 2026Updated 3 months ago
- Awesome cloud enumeratorβ1,148Mar 9, 2025Updated last year
- Quiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.β216Jun 23, 2020Updated 6 years ago
- Take a list of domains/subdomains and probe for working http/https server.β192Sep 8, 2020Updated 6 years ago
- The Swiss Army knife for automated Web Application Testingβ2,375Jun 20, 2026Updated 3 months ago
- π Enumerate git repository URL from list of URL / User / Org. Friendly to pipelineβ56Nov 24, 2024Updated last year
- Python utility to takeover domains vulnerable to AWS NS Takeoverβ86Feb 2, 2023Updated 3 years ago
- Scan for misconfigured S3 buckets across S3-compatible APIs!β3,176Aug 3, 2026Updated last month
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Making Favicon.ico based Recon Great again !β1,309Aug 29, 2023Updated 3 years ago
- Recursive DNS Subdomain Enumerator with dead-end avoidance system (BETA)β146Apr 9, 2021Updated 5 years ago
- SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcingβ91May 10, 2020Updated 6 years ago
- Enumerate AWS cloud resources based on provided credentialβ52May 11, 2022Updated 4 years ago
- The format of various s3 buckets is convert in one format. for bugbounty and security testing.β91May 6, 2023Updated 3 years ago
- RMIScout uses wordlist and bruteforce strategies to enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilitiesβ446Sep 7, 2022Updated 4 years ago
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.β535Mar 7, 2022Updated 4 years ago
- Pythonize Intruder Payloadβ13Dec 15, 2020Updated 5 years ago
- Petaq - Purple Team Command & Control Serverβ102Dec 8, 2022Updated 3 years ago
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ASN target organization IP range attack surface mapping for reconnaissance, fast and lightweightβ220Apr 10, 2022Updated 4 years ago
- A handy DNS service written in Go to aid in the detection of several types of blind vulnerabilities. It monitors a pentester's server forβ¦β194Sep 6, 2020Updated 6 years ago
- #JavascriptRecon #bugbountyβ21Aug 18, 2021Updated 5 years ago
- Signatures for jaeles scanner by @j3ssieβ116Apr 20, 2024Updated 2 years ago
- A fast tool to scan SAAS,PAAS App written in Goβ85Feb 13, 2023Updated 3 years ago
- Python library and CLI for the Bug Bounty Recon APIβ228Jul 3, 2026Updated 2 months ago
- find hardcoded strings from source codeβ286Feb 3, 2022Updated 4 years ago