A powerful containerized tool that automatically downloads, extracts, and scans packages from PyPI and npm for embedded secrets, API keys, tokens, and other sensitive information using TruffleHog.
☆20Jul 25, 2025Updated last year
Alternatives and similar repositories for revelio-scan
Users that are interested in revelio-scan are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Data about all known supply-chain attacks through history☆76Updated this week
- View screenshots as a slideshow over http☆15Mar 13, 2020Updated 6 years ago
- A tool to scan for .DS_Store files on webservers☆35Mar 28, 2021Updated 5 years ago
- Lab exercises to practice privilege escalation scenarios in AWS IAM. These exercises and the slides go through the basics behind AWS IAM,…☆16Oct 31, 2019Updated 6 years ago
- ☆12Mar 9, 2026Updated 4 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Siphon converts virtually any content source into clean, readable Markdown. Built for developers, pentesters, appsec professionals, and a…☆15Mar 14, 2026Updated 4 months ago
- Pentesting post exploitation tool for slack☆33Apr 3, 2026Updated 3 months ago
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆564Jul 20, 2026Updated last week
- Detect phantom IAM users, decode leaked AWS Bedrock and Claude Platform API keys, and prevent LLMjacking. CLI + SCPs + SIEM detection rul…☆34Jul 15, 2026Updated 2 weeks ago
- Audit content (pdfs, media files, images) sensitivity on urls☆45Jun 2, 2026Updated last month
- LobotoMl is a set of scripts and tools to assess production deployments of ML services☆10May 16, 2022Updated 4 years ago
- A GitHub Actions Supply Chain CTF / Goat☆28Apr 13, 2026Updated 3 months ago
- FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).☆182Jul 8, 2024Updated 2 years ago
- DEFCON 33 Workshop - Open Source Malware 101 - Everything you always wanted to know about npm malware (and more)☆16Aug 8, 2025Updated 11 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- GHAST (GitHub Actions Static Analysis Tool) is a tool to analyze the security posture of your GitHub Actions and its surrounding environm…☆20Aug 29, 2023Updated 2 years ago
- All of our GitHub Actions rolled into one. Or as we like to say: One GitHub Action to rule them all!☆21Jun 7, 2023Updated 3 years ago
- Regex based secret scanner for sccm deployment points sccmcontentlib$ shares. Find secrets automatically and download entire packages for…☆18Aug 13, 2025Updated 11 months ago
- Scripts for collecting metrics of the attack surface☆15Jun 10, 2021Updated 5 years ago
- my nuclei templates☆41Apr 21, 2024Updated 2 years ago
- Burp extension that add a tab to edit Office Open XML document (xlsx,docx,pptx)☆13Jan 5, 2018Updated 8 years ago
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆168May 8, 2026Updated 2 months ago
- A GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, sta…☆25Jun 7, 2023Updated 3 years ago
- *Unofficial* lgtm.com CLI — Use at your own risk. Also don't add more than 3K projects to "My projects" list.☆13Feb 21, 2022Updated 4 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Start of an Internet draft on the separation between HTTP's semantic layer, framing layer(s), and the underlying transport layer.☆15Mar 22, 2016Updated 10 years ago
- Enumerate SSN (System Service Numbers or Syscall ID) and syscall instruction address in ntdll module by parsing the PEB of the current pr…☆22Jan 28, 2024Updated 2 years ago
- Comprehensive AWS cloud reconnaissance and privilege escalation toolkit written in Python. Features IAM, EC2, S3, Lambda, ECS, Secrets Ma…☆50Jul 8, 2025Updated last year
- Burp_Suite-Antigravity_AI-Bug_Bounty_Hunter☆64Feb 9, 2026Updated 5 months ago
- Sockstress (CVE-2008-4609) DDoS implementation written in Go☆17Jul 2, 2016Updated 10 years ago
- A simple self-hosted RSS reader with AI article summarization feature. 🧶☕️📜☆11Apr 18, 2026Updated 3 months ago
- Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets☆52Dec 8, 2022Updated 3 years ago
- Finds graphql queries in javascript files☆69May 18, 2024Updated 2 years ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆168Updated this week
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Proof of Concepts for malicious maintainers: How to Tamper with Releases built with GitHub Actions Worfklows, presented at fwd:cloudsec E…☆85Sep 16, 2025Updated 10 months ago
- Rust declarations crate for the `libmagic` C library☆11Updated this week
- The utility aims to clean up output generated by popular tools by calculating a hash based on specific JSON values to removing junk data.☆16Apr 5, 2024Updated 2 years ago
- Dump exposed HTTP .git fast☆53Nov 11, 2022Updated 3 years ago
- mewt is a mutation testing framework☆50Jul 22, 2026Updated last week
- A library for building tools to determine if vulnerabilities are reachable in a code base.☆17Aug 19, 2025Updated 11 months ago
- SBOM Move - Automate build and transfer of SBOMs across systems☆27Jul 10, 2026Updated 2 weeks ago