A powerful containerized tool that automatically downloads, extracts, and scans packages from PyPI and npm for embedded secrets, API keys, tokens, and other sensitive information using TruffleHog.
☆20Jul 25, 2025Updated last year
Alternatives and similar repositories for revelio-scan
Users that are interested in revelio-scan are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Data about all known supply-chain attacks through history☆78Aug 12, 2026Updated 3 weeks ago
- Provides a consistent API around some existing scanning tools to integrate them with the rest of the tool kit☆25Updated this week
- View screenshots as a slideshow over http☆15Mar 13, 2020Updated 6 years ago
- A tool to scan for .DS_Store files on webservers☆35Mar 28, 2021Updated 5 years ago
- SecureStack Application Bill of Materials (ABOM/SBOM)☆13Aug 26, 2022Updated 4 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Lab exercises to practice privilege escalation scenarios in AWS IAM. These exercises and the slides go through the basics behind AWS IAM,…☆16Oct 31, 2019Updated 6 years ago
- ☆12Mar 9, 2026Updated 5 months ago
- Pentesting post exploitation tool for slack☆33Aug 19, 2026Updated 2 weeks ago
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.☆587Jul 20, 2026Updated last month
- Detect phantom IAM users, decode leaked AWS Bedrock and Claude Platform API keys, and prevent LLMjacking. CLI + SCPs + SIEM detection rul…☆36Aug 5, 2026Updated last month
- Audit content (pdfs, media files, images) sensitivity on urls☆45Jun 2, 2026Updated 3 months ago
- PoC's and Slides from 'Gophers, whales and.. clouds? Oh my!' BSides Wellington presentation by Glenn 'devalias' Grant☆17Mar 3, 2018Updated 8 years ago
- A GitHub Actions Supply Chain CTF / Goat☆29Apr 13, 2026Updated 4 months ago
- Personal "King of The Hill" toolkit.☆16Nov 5, 2024Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).☆182Jul 8, 2024Updated 2 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Sep 6, 2021Updated 5 years ago
- DEFCON 33 Workshop - Open Source Malware 101 - Everything you always wanted to know about npm malware (and more)☆16Aug 8, 2025Updated last year
- GHAST (GitHub Actions Static Analysis Tool) is a tool to analyze the security posture of your GitHub Actions and its surrounding environm…☆20Aug 29, 2023Updated 3 years ago
- Regex based secret scanner for sccm deployment points sccmcontentlib$ shares. Find secrets automatically and download entire packages for…☆18Aug 13, 2025Updated last year
- Scripts for collecting metrics of the attack surface☆15Jun 10, 2021Updated 5 years ago
- my nuclei templates☆41Apr 21, 2024Updated 2 years ago
- Example of using Dhall to generate a terraform file to manage a Github Organisation☆11Dec 8, 2020Updated 5 years ago
- Burp extension that add a tab to edit Office Open XML document (xlsx,docx,pptx)☆13Jan 5, 2018Updated 8 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆171May 8, 2026Updated 3 months ago
- A GitHub Action that creates a SBOM from your application so you can meet compliance and security requirements. Add this to your dev, sta…☆25Jun 7, 2023Updated 3 years ago
- GitHub action to generate a CycloneDX SBOM for Node.js☆23Jul 11, 2025Updated last year
- *Unofficial* lgtm.com CLI — Use at your own risk. Also don't add more than 3K projects to "My projects" list.☆13Feb 21, 2022Updated 4 years ago
- Start of an Internet draft on the separation between HTTP's semantic layer, framing layer(s), and the underlying transport layer.☆15Mar 22, 2016Updated 10 years ago
- Enumerate SSN (System Service Numbers or Syscall ID) and syscall instruction address in ntdll module by parsing the PEB of the current pr…☆22Jan 28, 2024Updated 2 years ago
- A simple reflective dll example☆19Jan 8, 2017Updated 9 years ago
- A simple self-hosted RSS reader with AI article summarization feature. 🧶☕️📜☆11Apr 18, 2026Updated 4 months ago
- Finds graphql queries in javascript files☆69May 18, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets☆52Dec 8, 2022Updated 3 years ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆182Updated this week
- Rust declarations crate for the `libmagic` C library☆11Updated this week
- The utility aims to clean up output generated by popular tools by calculating a hash based on specific JSON values to removing junk data.☆16Apr 5, 2024Updated 2 years ago
- Dump exposed HTTP .git fast☆53Nov 11, 2022Updated 3 years ago
- mewt is a mutation testing framework☆56Aug 12, 2026Updated 3 weeks ago
- A library for building tools to determine if vulnerabilities are reachable in a code base.☆17Aug 19, 2025Updated last year