17 dépôts
Comprehensive toolkits and browser extensions for web application security testing.
Explore 17 awesome GitHub repositories matching part of an awesome list · Penetration Testing Tools. Refine with filters or upvote what's useful.
Immersive Translate is a browser-based translation tool that integrates third-party translation engines and large language models to provide automated, real-time text conversion directly within the web interface. It functions as a browser extension that intercepts and modifies web content, injecting translated text nodes into the document object model to maintain original page layouts and styling. The project distinguishes itself through its granular control over the translation process, allowing users to define site-specific rules, manage custom terminology glossaries, and customize translat
Translation tool for analyzing foreign language web content.
Yakit is a comprehensive cybersecurity all-in-one platform designed for security assessments. It integrates a suite of core tools including an HTTP interception proxy for real-time traffic modification, an out-of-band interaction detector for verifying remote command execution via TCP, DNSLog, and ICMP, and a reverse shell manager for controlling remote server connections. The platform is distinguished by its dedicated security scripting environment, which allows for the development and execution of custom logic and plugins using a specialized high-performance language. It further extends fun
Integrated security testing platform for web applications.
ZeroOmega is a web-based proxy orchestrator and manager designed for real-time updates to active network gateways. It functions as a system for configuring, storing, and switching between different network proxy profiles to direct internet traffic. The project features a PAC script generator that translates structured proxy profile data into auto-configuration files. These scripts automate network routing decisions by matching requested URLs against defined patterns. Administration is handled through a browser-based interface that allows for the modification of routing rules and the manageme
Proxy management extension for browser-based testing.
Ce projet est un formateur et visualiseur JSON basé sur le web conçu pour le débogage structurel et l'exploration de données. Il transforme les chaînes JSON brutes en une structure arborescente lisible présentant la coloration syntaxique, des guides d'indentation et des nœuds repliables. L'outil fournit un visualiseur de données pour comparer les réponses brutes du serveur avec les représentations analysées. Il inclut également un exportateur de console qui envoie les données JSON analysées vers la console de développement du navigateur en tant que variable globale pour une inspection et une manipulation immédiates. Le système couvre l'inspection des réponses API et l'analyse de structure JSON, permettant aux utilisateurs de basculer entre le texte brut et les vues formatées pour vérifier des données imbriquées complexes.
Extension for formatting and inspecting JSON responses.
HaE is a network traffic analysis tool designed to extract, classify, and highlight specific data fragments within network messages and HTTP traffic. It functions as an HTTP data extractor and traffic content filter, utilizing a network metadata aggregator to centralize highlighted data fragments and annotations for analysis. The tool identifies high-value network packets by mapping classification results to visual color markers and employs a modular classification system to isolate data fragments from binary or text streams. It distinguishes the severity of matched data by piping extracted c
Burp Suite extension for highlighting and extracting sensitive data.
BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件
Burp Suite extension for handling various cryptographic operations.
A powerful browser extension to create, edit and delete cookies
Extension for managing and manipulating browser cookies.
Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。
Burp Suite extension for automated request/response decoding.
Extension for rendering markdown documentation during assessments.
Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件
Burp Suite extension for scanning routing-related vulnerabilities.
Log4j2 RCE Passive Scanner plugin for BurpSuite
Burp Suite scanner for identifying Log4j vulnerabilities.
Integration tool between different security testing platforms.
Burp Suite extension for decrypting session keys.
Extension for testing web application behavior without JavaScript.
Tool for discovering sensitive information in web source code.