How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
XSStrike is an automated security scanning engine designed for web application discovery, input
This project is a centralized repository and research database dedicated to the collection of technical documentation and source code concerning offensive security, malware development, and system exploitation. It serves as an archive for security professionals and researchers to study threat actor methodologies and historical security research. The repository functions as a static, version-controlled archive that organizes research papers and code samples into a flat-file directory structure. This approach ensures long-term availability and offline access to the materials, while a decentrali
BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and
BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS vulnerabilities
XSS'OR - Hack with JavaScript.
The main features of evilcos/xssor2 are: Offensive Security, XSS Injection.
Open-source alternatives to evilcos/xssor2 include: s0md3v/xsstrike — XSStrike is an automated security scanning engine designed for web application discovery, input. vxunderground/vxug-papers — This project is a centralized repository and research database dedicated to the collection of technical documentation… beefproject/beef — BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It… bugbountyforum/xss-radar — Cross-site scripting discovery A Chrome extension for fast and easy XSS fuzzing. cobbr/covenant — Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It… bitthebyte/bitblinder — BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS…