daffainfo / Git-SecretLinks
Go scripts for finding sensitive data like API key / some keywords in the github repository
☆161Updated 3 years ago
Alternatives and similar repositories for Git-Secret
Users that are interested in Git-Secret are comparing it to the libraries listed below
Sorting:
- Go scripts for checking API key / access token validity☆216Updated 4 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆131Updated 4 years ago
- a Go code to detect leaks in JS files via regex patterns☆146Updated 3 years ago
- ☆171Updated 3 years ago
- IP Lookups for Open Ports and Vulnerabilities from internetdb.shodan.io☆131Updated 3 years ago
- Enumerate Subdomains Through Google Dorks (Bypassed Page Filter)☆125Updated 2 months ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆81Updated 2 years ago
- A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration☆78Updated 5 years ago
- A blind XSS detection and XSS data capture framework☆172Updated last week
- Prototype pollution scanner using headless chrome☆219Updated 3 years ago
- Automated Web Recon Shell Scripts☆52Updated 3 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆164Updated 4 years ago
- 🔭 Collection of regexp pattern for security passive scanning☆115Updated 2 years ago
- GitHub Recon — and what you can achieve with it!☆121Updated 4 years ago
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆295Updated 11 months ago
- Turns any junk text into a usable wordlist for brute-forcing.☆224Updated last year
- Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency logs☆96Updated 4 years ago
- ☆96Updated 5 years ago
- A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)☆122Updated 3 years ago
- Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, al…☆178Updated 4 years ago
- Check AWS S3 instances for read/write/delete access☆121Updated 3 years ago
- Full Nuclei automation script with logic explanation.☆245Updated 3 years ago
- A reverse whois tool based on Whoxy API.☆166Updated last year
- Get related domains / subdomains by looking at Google Analytics IDs☆250Updated 3 years ago
- xss development frameworks, with the goal of making payload writing easier.☆147Updated last year
- Vulnerable NodeJS Web Application☆97Updated last year
- A Fast Broken Link Hijacker Tool written in Python☆100Updated last year
- R3C0Nizer is the first ever CLI based menu-driven web application B-Tier recon framework.☆154Updated 4 years ago
- A very (very) FAST and simple subdomain finder based on online & free services. Without any configuration requirements.☆113Updated 10 months ago
- Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.☆150Updated 2 years ago