nielsing / yarLinks
Yar is a tool for plunderin' organizations, users and/or repositories.
β238Updated 4 years ago
Alternatives and similar repositories for yar
Users that are interested in yar are comparing it to the libraries listed below
Sorting:
- Find cloud assets that no one wants exposed π βοΈβ348Updated 4 years ago
- A tool for identifying misconfigured CloudFront domainsβ360Updated 5 years ago
- Benchmarking repo for secrets scanningβ234Updated 11 months ago
- A simple HTTP(S) and DNS Canary bot with Slack/Discord/MS Teams/Lark/Telegram & Pushover supportβ296Updated 2 months ago
- Uncover forgotten secrets and bring them back to life, haunting security and operations teams.β207Updated 2 years ago
- Declarative penetration testing orchestration frameworkβ292Updated 5 years ago
- Fast and stealthy Amazon S3 bucket enumeration tool for pentesters.β251Updated 2 months ago
- barq: The AWS Cloud Post Exploitation framework!β387Updated 2 years ago
- Search exposed EBS volumes for secretsβ297Updated 2 years ago
- A tool for automatically gathering sensitive information from exposed Jenkins serversβ104Updated 2 years ago
- Monitors Github for leaked secretsβ200Updated 8 months ago
- These are the regexes that power truffleHogβ217Updated 2 years ago
- FestIn - Open S3 Bucket Scannerβ234Updated 4 years ago
- Finding exposed secrets and personal data in GitLabβ199Updated 8 months ago
- Monitoring GitHub for sensitive data shared publiclyβ66Updated 3 years ago
- AWS S3 Bucket/Object Finderβ120Updated 4 years ago
- A tool to enumerate S3 buckets manually or via certstreamβ82Updated 2 years ago
- Pentester-focused Docker registry tool to enumerate and pull imagesβ111Updated 5 years ago
- A simple file-based scanner to look for potential AWS access and secret keys in filesβ93Updated last year
- secretz, minimizing the large attack surface of Travis CIβ327Updated 3 years ago
- Scans Slack for API tokens, credentials, passwords, and more using YARA rulesβ40Updated 4 years ago
- rapid content discovery tool for recursively querying webservers, handy in pentesting and web application assessmentsβ247Updated 5 years ago
- β126Updated 5 years ago
- A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.β564Updated 2 years ago
- Hayat is a script for report and analyze Google Cloud Platform resources.β80Updated 5 years ago
- An open source intelligence tool to crawl the graph of certificate Alternate Namesβ353Updated last year
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.β78Updated 4 years ago
- Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Applicaβ¦β480Updated 6 years ago
- An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.β401Updated 4 years ago
- Golang-based subdomain miner leveraging certificate transparency logsβ76Updated last year