m14r41 / scan4secretsLinks
SAST and DAST Scan Supported with 400 plus rules available for secrets and allow you add your own wordlist as well. lightweight  source code scanner and for URL that detects hardcoded secrets like API keys, credentials, and sensitive information across files and folders.
☆102Updated 2 months ago
Alternatives and similar repositories for scan4secrets
Users that are interested in scan4secrets are comparing it to the libraries listed below
Sorting:
- Frogy 2.0 is an automated external reconnaissance and Attack Surface Management (ASM) toolkit☆263Updated this week
- ☆94Updated 6 months ago
- Ultimate Tasks Automation Framework for Hackers, DevSecOps, Pentesters, and Bug-bounty hunters!☆153Updated last month
- Advanced CORS Header Checker Tool with Vulnerability Detection and Bypass Attempts☆65Updated 4 months ago
- ☆47Updated 7 months ago
- IDOR Scanner is a Burp Suite extension that automates the detection and enumeration of potentially vulnerable numeric fields to identify …☆38Updated 8 months ago
- Search for all leaked keys/secrets using one regex! bugbounty☆142Updated 7 months ago
- This repository contains my writeups for the labs in PortSwigger's Web Security Academy platform. Each lab writeup includes the lab's nam…☆102Updated 3 months ago
- AI/LLM local model integration for analysis of reconftw results☆84Updated 5 months ago
- Analyze Android native `.so` files☆85Updated 3 months ago
- Parse FFUF results in GUI with option to sort based by response code , size , keyword☆99Updated last year
- An advanced JWT extraction & decoding tool for bug bounty hunters! 🏴☠️☆45Updated 7 months ago
- SubCerts is a simple tool that uses certificate transparency logs (via crt.sh) to extract subdomains of a given domain.☆74Updated 3 months ago
- This script automates SQL injection testing using SQLMap with AI-powered decision making.☆24Updated 4 months ago
- Zzl is a reconnaissance tool that collects subdomains from SSL certificates in IP ranges☆44Updated last year
- Unwaf is a Go tool designed to help identify WAF bypasses using passive techniques, such as: SPF records and DNS history. By default, Unw…☆98Updated 3 months ago
- ☆190Updated 6 months ago
- ☆78Updated 4 months ago
- dnsprober is a fast and multipurpose DNS reconnaissance tool designed for efficient DNS probing and enumeration. It supports multiple DNS…☆33Updated 4 months ago
- Blinks is a powerful Burp Suite extension that automates active scanning with Burp Suite Pro and enhances its functionality. With the int…☆138Updated 10 months ago
- A passive way to find backups/ sensitive information.☆88Updated 3 months ago
- Official TruffleHog Burp Suite Extension. Scan Burp Suite traffic for 800+ different types of secrets (API keys, passwords, SSH keys, etc…☆80Updated 7 months ago
- Dnsbruter is a powerful tool designed to perform active subdomain enumeration and discovery. It uses DNS resolution to efficiently brutef…☆123Updated 10 months ago
- A Powerful Recon Engine☆68Updated 11 months ago
- ☆94Updated 8 months ago
- SubOwner - A Simple tool check for subdomain takeovers.☆117Updated last year
- GBounty is a multi-step website vulnerability scanner developed in Golang designed to help companies, pentesters, and bug hunters identif…☆148Updated 2 months ago
- GarudRecon automates domain recon with top open-source tools to discover assets, enumerate subdomains, and detect XSS, SQLi, LFI, RCE & m…☆168Updated 2 weeks ago
- A cheatsheet of tools and commands that I use to pentest Active Directory.☆51Updated 3 years ago
- Discovering Typo Squatting on your domains!☆77Updated last year