Kali Linux

Dora : Find Exposed API Keys Based On RegEx And Get Exploitation Methods

Dora, a tool to Find Exposed API Keys Based On RegEx And Get Exploitation Methods For Some Of Keys That Are Found

Features

  • Blazing fast as we are using ripgrep in backend
  • Exploit/PoC steps for many of the API key, allowing to write a good report for bug bounty hunting
  • Unlike many other API key finders, dora also shows the path to the file and the line with context for easier analysis
  • Can easily be implemented into scripts. See Example Use Cases

Installation

Make sure to install ripgrep

clone the repo
git clone https://github.com/sdushantha/dora.git
change the working directory to sherlock
cd dora
install dora
python3 setup.py install –user

Usage

$ dora –help
usage: dora [options]
positional arguments:
PATH Path to directory or file to scan
optional arguments:
-h, –help show this help message and exit
–rg-path RG_PATH Specify path to ripgrep
–rg-arguments RG_ARGUMENTS
Arguments you want to provide to ripgrep
–json JSON Load regex data from a valid JSON file (default: db/data.json)
–verbose, -v, –debug, -d
Display extra debugging information
–no-color Don’t show color in terminal output

Example Use Cases

  • Decompile an APK using apktool and run dora to find exposed API keys
  • Scan GitHub repos by cloning it and allowing dora to scan it
  • While scraping sites, run dora to scan for API keys
R K

Recent Posts

Best AI Tools for OSINT 2026: Automate Research Without Losing Accuracy

AI is changing OSINT, but it is not replacing human verification. In 2026, the best…

7 hours ago

OSINT Framework Website List of Tools: Best Categories for Beginners

The OSINT Framework website list of tools is one of the easiest ways to start…

7 hours ago

Tor Browser Ubuntu: Install and Configure It Securely

Protecting online privacy has become increasingly important, and Tor Browser Ubuntu installations offer one of…

7 hours ago

Install Apache Cassandra on Ubuntu: Complete Setup Guide

Apache Cassandra is a powerful open-source NoSQL database designed for high availability, fault tolerance, and…

8 hours ago

Install Postman Ubuntu: Complete Setup Guide for Developers

Postman has become one of the most widely used tools for API development and testing.…

9 hours ago

OSINT Framework Official Website: Categories, Use Cases and Safer Alternatives

The OSINT Framework official website is one of the easiest places to start open-source intelligence…

1 day ago