daffainfo / Git-Secret
Go scripts for finding sensitive data like API key / some keywords in the github repository
☆160Updated 2 years ago
Alternatives and similar repositories for Git-Secret:
Users that are interested in Git-Secret are comparing it to the libraries listed below
- IP Lookups for Open Ports and Vulnerabilities from internetdb.shodan.io☆122Updated 2 years ago
- Turns any junk text into a usable wordlist for brute-forcing.☆218Updated 10 months ago
- Go scripts for checking API key / access token validity☆215Updated 3 years ago
- Full Nuclei automation script with logic explanation.☆242Updated 2 years ago
- Secret and/or credential patterns used for gf.☆237Updated last year
- Enumerate Subdomains Through Google Dorks☆123Updated 3 years ago
- Find endpoints on GitHub.☆191Updated last year
- A reverse whois tool based on Whoxy API.☆161Updated 10 months ago
- A Fast Broken Link Hijacker Tool written in Python☆99Updated 9 months ago
- Prototype pollution scanner using headless chrome☆216Updated 2 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆130Updated 3 years ago
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆180Updated 2 years ago
- a Go code to detect leaks in JS files via regex patterns☆140Updated 3 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆162Updated 3 years ago
- The scripts I write to help me on my bug bounty hunting☆121Updated 3 years ago
- Build your own reconnaissance system with Osmedeus Next Generation☆183Updated 4 months ago
- GitHub Recon — and what you can achieve with it!☆111Updated 3 years ago
- mx-takeover focuses DNS MX records and detects misconfigured MX records.☆346Updated last year
- Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, al…☆176Updated 4 years ago
- 🔭 Collection of regexp pattern for security passive scanning☆115Updated last year
- Go script for bypassing 403 forbidden☆150Updated 3 years ago
- A replacement of "qsreplace", accepts URLs as standard input, replaces all query string values with user-supplied values and stdout.☆104Updated 2 years ago
- List of reporting templates I have used since I started doing BBH.☆247Updated 4 months ago
- Customisable and automated HTTP header injection☆242Updated 7 months ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆265Updated last year
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆294Updated 4 months ago
- Check AWS S3 instances for read/write/delete access☆120Updated 2 years ago
- ☆148Updated last year
- Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools☆271Updated 6 months ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆80Updated 2 years ago