This tool checks every maintainer from every package in the NPM and Python Pypi registry for unregistered domains or unregistered MX records on those domains. Download the package index first! This can take a long time as the server is extremely slow (takes more than 30 mins): wget https://skimdb.npmjs.com/registry/_all_docs After this simply run the tool with ./hijagger npm. To see all options use the --help switch. The output is automatically saved to output.txt too. This tool will most probably run multiple days due to the high number of packages. To easily find the tool's output, you can use the following command: grep -i 'package' output.txt | less
FEATURES
ALTERNATIVES
TANNER is a remote data analysis and classification service for evaluating HTTP requests and composing responses for SNARE.
An extensible, heuristic-based vulnerability scanning tool for installed npm packages.
A collection of SQL injection cheat sheets for various databases
Python-based extension for integrating a Yara scanner into Burp Suite for on-demand website scans based on custom rules.
Deliberately vulnerable web application for security professionals to practice attack techniques.
FullHunt is a next-generation attack surface security platform that enables companies to discover, monitor, and secure their external attack surfaces.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.