This is your work, valued

France

Sébastien Copin

Advanced
@cosad3s

Independent Cybersecurity Engineer

postleaks. Search for sensitive data in Postman public library.

218

hfinder. Help recon of hostnames from specific ASN or CIDR, thanks to Robtex and BGP.HE

53

CVE-2022-35914-poc. Python

51

salsa. SALSA 💃⚡ - SALesforce Scanner for Aura (and beyond). Enumeration of vulnerabilities and misconfigurations against Salesforce endpoint.

31

njsdump. Dump paths & pages from Next.js Manifest

16

sonarleaks. Digging into private data through Sonarcloud public projects

11

subscout. All-in-one subdomains scout tool Docker image

7

DefaultCreds-cheat-sheet. One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️

3

magtek-card-reader. Read Triple-track Magnetic Stripe Card from Magtek Swipe Card Reader

3

badsecrets. A library for detecting known secrets across many web frameworks

3

related-domains. Find related domains of a given domain.

2

puncia. The Panthera(P.)uncia of Cybersecurity - Subdomain & Exploit Hunter powered by AI

2

horusec-platform. Fork of ZupIT/horusec-platform

2

sret. Salesforce Recon and Exploitation Toolkit

2

jappalyzer. A Java implementation of the Wappalyzer.

2

ApacheTomcatScanner. A python script to scan for Apache Tomcat server vulnerabilities.

2

graphql-introspection-converter. Simple converter for GraphQL introspection JSON to schema

2

sessionless. SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

1

hacktricks-cloud. Python

1

badPods. A collection of manifests that will create pods with elevated privileges.

1

wappalyzer. HTTP Archive fork of Wappalyzer

1

netscan. Network scanner

1

tapestry4-examples-docker. Working Apache Tapestry 4 examples on Apache Tomcat embedded in Docker image

1