A BOLA/IDOR access-control confirmation engine — code adjudicates every verdict, not just the model, with a reproducible evidence chain.
-
Updated
Aug 15, 2026 - Python
A BOLA/IDOR access-control confirmation engine — code adjudicates every verdict, not just the model, with a reproducible evidence chain.
SecScan is a fast, configurable secret scanning tool written in Go that detects API keys, tokens, credentials, and high-entropy secrets across source code and full Git history. Built for developers and CI pipelines, with strong defaults and low false positives.
DorkRecon is a domain reconnaissance tool generating Google dork queries (site:, filetype:, etc.) to find indexed, exposed data like configs, backups, and login pages. Designed for authorized penetration testing and red teaming, it checks domain exposure to secure leaks. It does not look up people and requires explicit authorization to run.
Guía interactiva completa: desde enumeración hasta root
Autonomous white-box security & code audit platform. Containerized CLI orchestrator for SAST, SARIF reporting, and API vulnerability assessments.
Burp Suite extension for automated multi-tenant IDOR/BOLA testing
Add a description, image, and links to the security-tools-testing topic page so that developers can more easily learn about it.
To associate your repository with the security-tools-testing topic, visit your repo's landing page and select "manage topics."