nikitastupin / pwnhub
How GitHub Actions workflows can be hacked
β119Updated 5 months ago
Alternatives and similar repositories for pwnhub:
Users that are interested in pwnhub are comparing it to the libraries listed below
- GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.β239Updated this week
- β180Updated 3 months ago
- Manager of third-party sources of Semgrep rules πβ78Updated 7 months ago
- Octoscan is a static vulnerability scanner for GitHub action workflows.β190Updated last month
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsβ101Updated 3 weeks ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.β256Updated 7 months ago
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β132Updated last year
- This tool analyzes a given Github repository and searches for dangling or force-pushed commits containing potential secret or interestingβ¦β155Updated 6 months ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.β153Updated 5 months ago
- PP-finder Help you find gadget for prototype pollution exploitationβ151Updated 6 months ago
- Nuclei plugins to audit Chrome extensionsβ63Updated 7 months ago
- truffleproc β hunt secrets in process memory (TruffleHog & gdb mashup)β114Updated last year
- Client-Side Prototype Pollution Toolsβ84Updated 3 years ago
- An extension to use Semgrep inside Burp Suite.β88Updated last year
- β149Updated last year
- boostsecurityio/lotpβ112Updated this week
- β164Updated 4 months ago
- β98Updated last year
- A collection of Server-Side Prototype Pollution gadgets and exploitsβ166Updated 2 weeks ago
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.β189Updated 6 months ago
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application aβ¦β156Updated 3 months ago
- CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).β104Updated last month
- Awesome MXSS ??β47Updated 4 months ago
- MetaSec.js combines all the free open-source security tools to identify issues with JavaScript and automates the boring partsβ80Updated 2 years ago
- Distribute ordinary bash commands over many systemsβ161Updated 2 years ago
- Semgrep queries developed by Trail of Bits.β383Updated last month
- Rust-based high performance domain permutation generator.β284Updated last year
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizationsβ55Updated last week
- openrisk is a tool that generates a risk score based on the results of a Nuclei scan.β167Updated 2 weeks ago
- Scans your Github Actions for security issuesβ57Updated this week