Skip to content

GitRecon is a lightweight and portable github reconnaissance tool, it searches for sensitive information like Secret Keys, Private Keys, AD credentials etc. commited/pushed to the Github public repositories.

Notifications You must be signed in to change notification settings

Somil-Keswani/GitRecon

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 

Repository files navigation

GitRecon

GitRecon is a lightweight and portable github reconnaissance tool, it searches for sensitive information like Secret Keys, Private Keys, AD credentials etc. commited/pushed to the Github public repositories.

It accepts Target Company Domain, Github Access Token and Prefilled Sensitive Info from dropdown box but it can also conduct repository scan optionally by accepting "Custom Keyword" making it powerfull tool having wider search coverage. The output contains the Repository path, URL and highlighted search keywords.

Deployment

It can be easily deployable with minimal dependency i.e webserver like Python-SimpleHTTPServer.

Follow the below steps to deploy the GitRecon:

  1. Clone the GitRecon repository.
  2. Place the repository's files in the webserver.
  3. Open the index.html to access the tool.

Output

Search results can be exported in CSV file, downloaded with Company Domain & search keyword mentioned in report's file name for future references.

GitRecon Page

GR_Landing_Page

Author

Somil Keswani

About

GitRecon is a lightweight and portable github reconnaissance tool, it searches for sensitive information like Secret Keys, Private Keys, AD credentials etc. commited/pushed to the Github public repositories.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages