Tool to search secrets in various filetypes.
☆1,034Apr 25, 2023Updated 2 years ago
Alternatives and similar repositories for DumpsterDiver
Users that are interested in DumpsterDiver are comparing it to the libraries listed below
Sorting:
- Scan for misconfigured S3 buckets across S3-compatible APIs!☆2,997Dec 11, 2025Updated 2 months ago
- A python script that finds endpoints in JavaScript files☆4,286Apr 13, 2024Updated last year
- A small tool that extracts relative URLs from a file.☆768Sep 23, 2020Updated 5 years ago
- A Tool for Domain Flyovers☆5,906May 22, 2022Updated 3 years ago
- A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, al…☆1,285Aug 18, 2025Updated 6 months ago
- The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.☆5,073Updated this week
- Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient☆1,556Oct 17, 2022Updated 3 years ago
- Contextual Content Discovery Tool☆3,096Apr 29, 2024Updated last year
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,650Jan 5, 2026Updated last month
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.☆532Mar 7, 2022Updated 3 years ago
- Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.☆646Nov 21, 2019Updated 6 years ago
- A tool for identifying misconfigured CloudFront domains☆362Jun 24, 2020Updated 5 years ago
- ☆2,316Dec 8, 2023Updated 2 years ago
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and…☆3,903Sep 27, 2021Updated 4 years ago
- Tools for fingerprinting and exploiting Amazon cloud infrastructures☆496Nov 10, 2022Updated 3 years ago
- Notes about attacking Jenkins servers☆2,090Jul 10, 2024Updated last year
- The Swiss Army knife for automated Web Application Testing☆2,322May 8, 2024Updated last year
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.☆2,029Jul 12, 2025Updated 7 months ago
- Awesome cloud enumerator☆1,100Mar 9, 2025Updated 11 months ago
- Generates permutations, alterations and mutations of subdomains and then resolves them☆2,474Jan 9, 2025Updated last year
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.☆6,082Aug 14, 2024Updated last year
- locate and attack Lync/Skype for Business☆346Oct 1, 2024Updated last year
- A tool to abuse Exchange services☆2,300Jun 10, 2024Updated last year
- Fetch many paths for many hosts - without killing the hosts☆1,693Feb 3, 2024Updated 2 years ago
- This tool can be used to brute discover GET and POST parameters☆1,393Aug 24, 2019Updated 6 years ago
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the ac…☆1,774Apr 26, 2024Updated last year
- HostHunter a recon tool for discovering hostnames using OSINT techniques.☆1,156Mar 30, 2023Updated 2 years ago
- Security Tool to Look For Interesting Files in S3 Buckets☆1,454Apr 10, 2024Updated last year
- retrieve information via O365 and AzureAD with a valid cred☆732Aug 14, 2022Updated 3 years ago
- Subdomain Takeover tool written in Go☆2,028Aug 13, 2023Updated 2 years ago
- A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.☆116Mar 29, 2019Updated 6 years ago
- A collection of tools to perform searches on GitHub.☆1,467Feb 9, 2023Updated 3 years ago
- Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.☆1,405Feb 10, 2026Updated 3 weeks ago
- Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.☆1,547Mar 7, 2024Updated last year
- Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling☆1,258Mar 19, 2025Updated 11 months ago
- GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep☆1,401Sep 13, 2024Updated last year
- AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation☆2,219Apr 3, 2023Updated 2 years ago
- A collection of AWS penetration testing junk☆1,220Aug 30, 2023Updated 2 years ago
- Automatic SSRF fuzzer and exploitation tool☆3,489Sep 4, 2025Updated 5 months ago