nielsing / yar
Yar is a tool for plunderin' organizations, users and/or repositories.
☆235Updated 4 years ago
Alternatives and similar repositories for yar:
Users that are interested in yar are comparing it to the libraries listed below
- Find cloud assets that no one wants exposed 🔎 ☁️☆335Updated 4 years ago
- A tool for automatically gathering sensitive information from exposed Jenkins servers☆103Updated 2 years ago
- secretz, minimizing the large attack surface of Travis CI☆325Updated 2 years ago
- Uncover forgotten secrets and bring them back to life, haunting security and operations teams.☆207Updated last year
- Fast and stealthy Amazon S3 bucket enumeration tool for pentesters.☆241Updated 2 weeks ago
- A tool for identifying misconfigured CloudFront domains☆349Updated 4 years ago
- A tool to enumerate S3 buckets manually or via certstream☆80Updated last year
- A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.☆555Updated last year
- Search exposed EBS volumes for secrets☆297Updated last year
- FestIn - Open S3 Bucket Scanner☆231Updated 4 years ago
- ☆274Updated 3 years ago
- rapid content discovery tool for recursively querying webservers, handy in pentesting and web application assessments☆243Updated 5 years ago
- Benchmarking repo for secrets scanning☆230Updated 5 months ago
- A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.☆397Updated 4 years ago
- An open source intelligence tool to crawl the graph of certificate Alternate Names☆346Updated 11 months ago
- vulnerable single sign on☆147Updated 6 months ago
- Burp with Friends☆101Updated 2 years ago
- A highly configurable Framework for easy automated web scanning☆370Updated 4 years ago
- AWS S3 Bucket/Object Finder☆118Updated 3 years ago
- Linux privilege escalation checks (systemd, dbus, socket fun, etc)☆290Updated 5 years ago
- A simple HTTP(S) and DNS Canary bot with Slack/Discord/MS Teams/Lark/Telegram & Pushover support☆293Updated 2 months ago
- A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.☆111Updated 5 years ago
- Powerful Visual Subdomain Enumeration at the Click of a Mouse☆138Updated 5 years ago
- Hayat is a script for report and analyze Google Cloud Platform resources.☆80Updated 5 years ago
- These are the regexes that power truffleHog☆215Updated 2 years ago
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆76Updated 4 years ago
- A tool to hunt for credentials in github wild AKA git*hunt☆293Updated 2 years ago
- ReconPi - A lightweight recon tool that performs extensive scanning with the latest tools.☆720Updated 2 years ago
- ☆124Updated 5 years ago
- Pentester-focused Docker registry tool to enumerate and pull images☆105Updated 5 years ago