active
19 resources across 1 kinds
Tools
- Open ↗GraphQL Copactive
Purpose-built GraphQL security audit for introspection, field suggestion, batching/DoS and CSRF issues.
- Open ↗Schemathesisactive
Property-based API testing from an OpenAPI/GraphQL spec, finding schema violations, 500s and missing-auth operations.
- Open ↗ShareFiltratoractivedual-usehigh-risk
A Python CLI that uses the SharePoint search API to discover and bulk-download files across SharePoint/OneDrive in an M365 tenant, targeting documents exposed by over-permissive sharing that may contain credentials or secrets. Uses authenticated browser session cookies and ships preset queries (Snaffpoint, Credentials).
- Open ↗pentest-tools (gwen001)activedual-use
Collection of ~60 custom Bash/Python/PHP utilities for quick pentest tasks: DNS enumeration and zone transfers, port scanning and ping sweeps, subdomain discovery via certificate transparency, web vulnerability checks (XSS, CORS, CRLF, SSRF, open redirect), and OSINT (Shodan, dorking). ~3.3k stars.