48 रिपॉजिटरी
Add-ons for Burp Suite, Caido, and ZAP to enhance testing.
Explore 48 awesome GitHub repositories matching part of an awesome list · Proxy Tool Extensions. Refine with filters or upvote what's useful.
HUNT Suite is a collection of Burp Suite Pro/Free and OWASP ZAP extensions. Identifies common parameters vulnerable to certain vulnerability classes (Burp Suite Pro and OWASP ZAP). Organize testing methodologies (Burp Suite Pro and Free).
Identify parameters vulnerable to common security issues.
A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅
Add useful context menu functions to Burp Suite.
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
Manage and organize custom security scanning rules.
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
Security testing tool for GraphQL endpoints.
Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.
High-speed brute-forcing and fuzzing tool.
Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist
Discover and analyze potential parameters in HTTP requests.
This extension identifies hidden, unlinked parameters. It's particularly useful for finding web cache poisoning vulnerabilities.
Automate discovery of hidden, unlinked parameters.
This Burp Suite extension automatically detects and exploits HTTP Request Smuggling vulnerabilities using advanced desynchronization techniques developed by PortSwigger researcher James Kettle. It supports comprehensive scanning for HTTP/1.1 and HTTP/2-downgrade desync vulnerabilities,…
Detect and exploit HTTP request smuggling vulnerabilities.
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
Automate authorization testing for web applications.
Burp Extension for a passive scanning JS files for endpoint links.
Extract links from JavaScript files.
A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques
Identify HTTP request smuggling vulnerabilities.
Blackbox Protobuf now has an official package on PyPi under the name bbpb. The blackboxprotobuf package is an older fork
Decode and modify arbitrary Protobuf messages.
Advanced Burp Suite Logging Extension
Advanced logging for Burp Suite requests and responses.
AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.
Automate authorization and access control testing.
Because just a dark theme wasn't enough!
Customize the visual appearance of Burp Suite.
A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal backend systems by causing pingbacks to Burp Collaborator
Identify OAST-based vulnerabilities.
This extension generates scripts to reissue a selected request. The scripts can be run outside of Burp. It can be useful to script attacks such as second order SQL injection, padding oracle, fuzzing encoded value, etc.
Generate scripts for HTTP request manipulation.
Automated blind-xss search for Burp Suite
Security testing utility for Burp Suite.
Dr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful information! It's your very own discovery side kick, the Dr. Watson to your Sherlock!
Find assets, subdomains, and sensitive keys during reconnaissance.
Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.
Detect vulnerable JavaScript libraries.