Tool · activeactivedual-usehigh-risk
ShareFiltrator
A Python CLI that uses the SharePoint search API to discover and bulk-download files across SharePoint/OneDrive in an M365 tenant, targeting documents exposed by over-permissive sharing that may contain credentials or secrets. Uses authenticated browser session cookies and ships preset queries (Snaffpoint, Credentials).
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
High risk of account lockouts, WAF bans, and terms-of-service violations. Requires explicit authorization and small, targeted inputs.
More tools
- CommixactiveAutomated command-injection detection and exploitation.
- CorsyactiveScans for CORS misconfigurations.
- CRLFuzzactiveProbes for CRLF injection and HTTP response splitting.
- DalfoxactiveXSS scanner for reflected, stored and DOM input surfaces with structured PoC output.
- GhauriactiveFast automated SQL-injection detection and exploitation, an sqlmap alternative.
- gowitnessactiveHeadless screenshot capture of web targets.