postleaks. Search for sensitive data in Postman public library.
218hfinder. Help recon of hostnames from specific ASN or CIDR, thanks to Robtex and BGP.HE
53CVE-2022-35914-poc. Python
51salsa. SALSA 💃⚡ - SALesforce Scanner for Aura (and beyond). Enumeration of vulnerabilities and misconfigurations against Salesforce endpoint.
31njsdump. Dump paths & pages from Next.js Manifest
16sonarleaks. Digging into private data through Sonarcloud public projects
11subscout. All-in-one subdomains scout tool Docker image
7DefaultCreds-cheat-sheet. One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
3magtek-card-reader. Read Triple-track Magnetic Stripe Card from Magtek Swipe Card Reader
3badsecrets. A library for detecting known secrets across many web frameworks
3related-domains. Find related domains of a given domain.
2puncia. The Panthera(P.)uncia of Cybersecurity - Subdomain & Exploit Hunter powered by AI
2horusec-platform. Fork of ZupIT/horusec-platform
2sret. Salesforce Recon and Exploitation Toolkit
2jappalyzer. A Java implementation of the Wappalyzer.
2ApacheTomcatScanner. A python script to scan for Apache Tomcat server vulnerabilities.
2graphql-introspection-converter. Simple converter for GraphQL introspection JSON to schema
2sessionless. SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens
1hacktricks-cloud. Python
1badPods. A collection of manifests that will create pods with elevated privileges.
1wappalyzer. HTTP Archive fork of Wappalyzer
1netscan. Network scanner
1tapestry4-examples-docker. Working Apache Tapestry 4 examples on Apache Tomcat embedded in Docker image
1