[redteam.to]
Tools Submit
← All tools

leaky-paths

https://github.com/ayoubfathi/leaky-paths
Free
Categories
Exploitation Password Attacks Reconnaissance Scanning & Enumeration
Description

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.

Keywords
appsec axiom bugbounty dirbuster dirsearch ffuf fuzzing hacktoberfest meg nuclei penetration-testing pentest recon redteam redteaming security security-tools subfinder wayback-machine wordlist
See also
graphql-cop
Open Source

Security Auditor Utility for GraphQL APIs…

cve-search_mcp
Open Source

A Model Context Protocol (MCP) server for querying the CVE-Search API…

Impacket-secretsdump
Open Source Kali

Dumps secrets remotely using a variety of techniques including DCSync (without running code on DC), …

25000-syllabified-words-list
Free

A word list containing 25,000 of the most common English words, divided into syllables.…

BurpSuite-Xkeys
Free

A Burp Suite Extension to extract interesting strings (key, secret, token, or etc.) from a webpage.…

horus
Open Source

An OSINT / digital forensics tool built in Python…

© 2026 redteam.to — The Pentest Tool Directory

For authorized security testing and educational use only.