nielsing / yar
Yar is a tool for plunderin' organizations, users and/or repositories.
β236Updated 4 years ago
Alternatives and similar repositories for yar:
Users that are interested in yar are comparing it to the libraries listed below
- Find cloud assets that no one wants exposed π βοΈβ338Updated 4 years ago
- Uncover forgotten secrets and bring them back to life, haunting security and operations teams.β207Updated last year
- secretz, minimizing the large attack surface of Travis CIβ325Updated 2 years ago
- Fast and stealthy Amazon S3 bucket enumeration tool for pentesters.β243Updated last week
- A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.β557Updated 2 years ago
- A tool for identifying misconfigured CloudFront domainsβ350Updated 4 years ago
- A tool to hunt for credentials in github wild AKA git*huntβ293Updated 2 years ago
- Search exposed EBS volumes for secretsβ297Updated last year
- A tool for automatically gathering sensitive information from exposed Jenkins serversβ103Updated 2 years ago
- A simple HTTP(S) and DNS Canary bot with Slack/Discord/MS Teams/Lark/Telegram & Pushover supportβ293Updated last week
- an asynchronous target enumeration toolβ243Updated 2 years ago
- barq: The AWS Cloud Post Exploitation framework!β387Updated 2 years ago
- β275Updated 3 years ago
- An open source intelligence tool to crawl the graph of certificate Alternate Namesβ347Updated last year
- FestIn - Open S3 Bucket Scannerβ231Updated 4 years ago
- Monitors Github for leaked secretsβ196Updated 4 months ago
- Finding exposed secrets and personal data in GitLabβ197Updated 4 months ago
- Pentester-focused Docker registry tool to enumerate and pull imagesβ105Updated 5 years ago
- A tool to enumerate S3 buckets manually or via certstreamβ82Updated last year
- Monitoring GitHub for sensitive data shared publiclyβ66Updated 3 years ago
- Hayat is a script for report and analyze Google Cloud Platform resources.β80Updated 5 years ago
- Python automation of Docker.sock abuseβ212Updated 2 years ago
- Cloud-related research releases from the Rhino Security Labs team.β381Updated 4 years ago
- ReconJSON is a project dedicated to creating a flexible and consistent JSON format across popular recon tools.β103Updated 6 years ago
- A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.β396Updated 4 years ago
- Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Applicaβ¦β481Updated 6 years ago
- Burp with Friendsβ102Updated 2 years ago
- Scans Slack for API tokens, credentials, passwords, and more using YARA rulesβ39Updated 4 years ago
- Benchmarking repo for secrets scanningβ230Updated 7 months ago
- Automatic finder for subdomains vulnerable to takeover. Written in Go, based on @haccer's subjack.β148Updated 4 years ago