cariddi
Developed by edoardottt
cariddi is an open-source, high-performance command-line tool written in Go, designed for security analysts and bug bounty hunters. It takes a list of domains, crawls their URLs, and scans for sensitive endpoints, credentials, API keys, tokens, file extensions, and more. It offers customizable configuration, including proxy support (compatible with BurpSuite), concurrency control, and regex-based secret hunting, while supporting HTML, JSON, and plain text outputs.
- Deep scanning for secrets, API keys, and tokens
- Custom endpoints and regex-based discovery
- Configurable concurrency, delays, and proxy support
- Multi-format reporting in HTML, JSON, and plain text
- Intensive crawling with smart domain filtering
desktop