lanrat / certgraph
An open source intelligence tool to crawl the graph of certificate Alternate Names
☆346Updated last year
Alternatives and similar repositories for certgraph:
Users that are interested in certgraph are comparing it to the libraries listed below
- A passive subdomain finder☆329Updated last year
- Fast and stealthy Amazon S3 bucket enumeration tool for pentesters.☆242Updated 3 weeks ago
- Search exposed EBS volumes for secrets☆297Updated last year
- Attack Surface Management since before Attack Surface Management was a thing☆634Updated this week
- Find cloud assets that no one wants exposed 🔎 ☁️☆335Updated 4 years ago
- Python library for connecting to CertStream☆435Updated 6 months ago
- Monitors Github for leaked secrets☆195Updated 3 months ago
- An OSINT tool that discovers sub-domains by searching Certificate Transparency logs☆469Updated 2 years ago
- Private key usage verification☆424Updated 2 months ago
- a tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain☆195Updated last year
- hardCIDR is a Linux Bash script, but also functions under macOS. Your mileage may vary on other distros. The script with no specified opt…☆369Updated 3 years ago
- Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"☆348Updated 4 years ago
- ☆274Updated 3 years ago
- Yar is a tool for plunderin' organizations, users and/or repositories.☆235Updated 4 years ago
- A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.☆555Updated last year
- A highly configurable Framework for easy automated web scanning☆370Updated 4 years ago
- A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.☆501Updated last year
- Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki☆202Updated 3 months ago
- nnposter's alternate fingerprint dataset for Nmap script http-default-accounts☆245Updated this week
- The request.bin of DNS request☆233Updated 6 years ago
- Monitor certificates generated for specific domain strings and associated, store data into sqlite3 database, alert you when sites come on…☆142Updated last week
- A tool geared towards pentesting APIs using OpenAPI definitions.☆174Updated 2 years ago
- A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.☆397Updated 4 years ago
- A golang utility to spider through a website searching for additional links.☆335Updated 4 years ago
- A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering☆209Updated 4 years ago
- These are the regexes that power truffleHog☆215Updated 2 years ago
- Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).☆123Updated last year
- Scan DockerHub images that match a keyword to find secrets.☆55Updated 4 years ago
- DNS Rebinding Exploitation Framework☆488Updated 3 years ago
- Find AWS S3 buckets and test their permissions.☆376Updated last year