17 Repos
Tools for discovering hidden endpoints, metadata, and sensitive information.
Explore 17 awesome GitHub repositories matching part of an awesome list · Sensitive Data Exposure. Refine with filters or upvote what's useful.
Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist
Discovers and analyzes potential parameters in web requests.
Burp Extension for a passive scanning JS files for endpoint links.
Passively scans JavaScript files to extract hidden endpoints.
A Burp Suite content discovery plugin that add the smart into the Buster!
Enhances content discovery and forced browsing capabilities.
A Burp Suite Extension to extract interesting strings (key, secret, token, or etc.) from a webpage.
Extracts sensitive strings like secrets and tokens from web pages.
This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.
Searches static files for sensitive information and interesting patterns.
Burp extension
Scans for sensitive files and directories during active testing.
X41 BeanStack - Stack Trace Fingerprinting BETA
Fingerprints Java applications using stack traces.
Sensitive Discoverer, a Burp extension to discovers sensitive information inside HTTP messages.
Automatically extracts sensitive data from HTTP responses.
This tool analyzes a given Gitlab repository and searches for dangling or force-pushed commits, containing potential secret or interesting information.
Extracts sensitive information from deleted GitLab commit history.
Sensitive Discoverer, a Burp extension to discovers sensitive information inside HTTP messages.
Discovers sensitive information within HTTP messages.
This extension makes a OPTIONS request and determines if other HTTP methods than the original request are available.
Identifies available HTTP methods on target endpoints.
This is a Burpsuite plugin built to enable you to import your directory bruteforcing results into burp for easy viewing later. This is an alternative to proxying bruteforcing tools through burp to catch the results.
Imports directory brute-forcing results for further analysis.
Burp-hash is a Burp Suite plugin.
Analyzes hashed parameters used in session tokens.
Build OpenApi specs for your APIs from Burp's traffic using Levo.ai. Also detect the PII in your APIs.
Generates OpenAPI specs and detects PII in traffic.
BurpSuite extension to assist with Automated Forced Browsing/Endpoint Enumeration
Assists with automated endpoint enumeration and forced browsing.
Headers Burp Extension
Automates the reporting of missing security headers.
The PDF Metadata Burp Extension provides an additional passive Scanner check for metadata in PDF files.
Passively scans PDF files for embedded metadata.