awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to ilmila/j2eescan

Projects sharing features with J2EEScan

30 open-source projects similar to ilmila/j2eescan, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • pmiaowu/burpshiropassivescanpmiaowu avatar

    pmiaowu/BurpShiroPassiveScan

    1,802View on GitHub↗

    一款基于BurpSuite的被动式shiro检测插件

    Java
    View on GitHub↗1,802
  • andresriancho/w3afandresriancho avatar

    andresriancho/w3af

    4,850View on GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    View on GitHub↗4,850
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Goattack-surfacecve-scannerdast
    View on GitHub↗29,189
  • skisw/fastjson-expS

    skisw/fastjson-exp

    0View on GitHub↗
    View on GitHub↗0

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • silentsignal/burp-image-sizesilentsignal avatar

    silentsignal/burp-image-size

    95View on GitHub↗

    Image size issues plugin for Burp Suite

    Java
    View on GitHub↗95
  • solomonsklash/sri-checkSolomonSklash avatar

    SolomonSklash/sri-check

    13View on GitHub↗

    A Burp Suite extension for identifying missing Subresource Integrity attributes.

    Python
    View on GitHub↗13
  • epinna/tplmapepinna avatar

    epinna/tplmap

    4,169View on GitHub↗

    tplmap is a security tool designed for the detection and exploitation of server-side template injection vulnerabilities. It functions as an automated scanner to identify vulnerable template engine contexts and provides a framework for achieving remote code execution. The tool focuses on translating high-level requests into engine-specific syntax to execute operating system commands and bypass application sandboxes. It further enables remote file system access, allowing users to read, write, and transfer files between a local machine and a target server. Additional capabilities include the ab

    Python
    View on GitHub↗4,169
  • cnotin/burp-scan-manual-insertion-pointcnotin avatar

    cnotin/burp-scan-manual-insertion-point

    11View on GitHub↗

    Burp Suite Pro extension

    Java
    View on GitHub↗11
  • pmiaowu/burpfastjsonscanpmiaowu avatar

    pmiaowu/BurpFastJsonScan

    1,247View on GitHub↗

    一款基于BurpSuite的被动式FastJson检测插件

    Java
    View on GitHub↗1,247
  • yandex/burp-molly-packyandex avatar

    yandex/burp-molly-pack

    140View on GitHub↗

    Security checks pack for Burp Suite

    Java
    View on GitHub↗140
  • portswigger/collaborator-everywherePortSwigger avatar

    PortSwigger/collaborator-everywhere

    447View on GitHub↗

    A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal backend systems by causing pingbacks to Burp Collaborator

    Java
    View on GitHub↗447
  • tijme/angularjs-csti-scannertijme avatar

    tijme/angularjs-csti-scanner

    324View on GitHub↗

    Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.

    Python
    View on GitHub↗324
  • silentsignal/burp-uuidsilentsignal avatar

    silentsignal/burp-uuid

    55View on GitHub↗

    UUID issues for Burp Suite

    Java
    View on GitHub↗55
  • snoopysecurity/noopener-burp-extensionsnoopysecurity avatar

    snoopysecurity/Noopener-Burp-Extension

    5View on GitHub↗

    Find Target="_blank" values within web pages that are set without 'noopener' and 'noreferrer' attributes

    Python
    View on GitHub↗5
  • augustd/burp-suite-gwt-scanaugustd avatar

    augustd/burp-suite-gwt-scan

    13View on GitHub↗

    Burp Suite plugin identifies insertion points for GWT (Google Web Toolkit) requests

    Java
    View on GitHub↗13
  • codingo/minesweepercodingo avatar

    codingo/Minesweeper

    203View on GitHub↗

    A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

    Python
    View on GitHub↗203
  • d35m0nd142/lfisuiteD35m0nd142 avatar

    D35m0nd142/LFISuite

    1,945View on GitHub↗

    Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

    Python
    View on GitHub↗1,945
  • dobin/burpsentineldobin avatar

    dobin/BurpSentinel

    153View on GitHub↗

    GUI Burp Plugin to ease discovering of security holes in web applications

    Java
    View on GitHub↗153
  • moloch--/csp-bypassmoloch-- avatar

    moloch--/CSP-Bypass

    167View on GitHub↗

    A Burp Plugin for Detecting Weaknesses in Content Security Policies

    Python
    View on GitHub↗167
  • hahwul/a2svhahwul avatar

    hahwul/a2sv

    634View on GitHub↗

    Auto Scanning to SSL Vulnerability

    Python
    View on GitHub↗634
  • vulnerscom/burp-vulners-scannervulnersCom avatar

    vulnersCom/burp-vulners-scanner

    897View on GitHub↗

    Vulnerability scanner based on vulners.com search API

    Java
    View on GitHub↗897
  • tsojan/tsojanscanTsojan avatar

    Tsojan/TsojanScan

    1,520View on GitHub↗

    An integrated BurpSuite vulnerability detection plug-in.

    View on GitHub↗1,520
  • f6jo/routevulscanF6JO avatar

    F6JO/RouteVulScan

    1,323View on GitHub↗

    Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件

    Java
    View on GitHub↗1,323
  • secdec/attack-surface-detector-burpsecdec avatar

    secdec/attack-surface-detector-burp

    113View on GitHub↗

    The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters

    Java
    View on GitHub↗113
  • portswigger/http-request-smugglerportswigger avatar

    portswigger/http-request-smuggler

    1,213View on GitHub↗

    This Burp Suite extension automatically detects and exploits HTTP Request Smuggling vulnerabilities using advanced desynchronization techniques developed by PortSwigger researcher James Kettle. It supports comprehensive scanning for HTTP/1.1 and HTTP/2-downgrade desync vulnerabilities,…

    Java
    View on GitHub↗1,213
  • projectdiscovery/naabuprojectdiscovery avatar

    projectdiscovery/naabu

    5,766View on GitHub↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Gocdn-exclusionhacktoberfestnmap
    View on GitHub↗5,766
  • knownsec/pocsuite3knownsec avatar

    knownsec/pocsuite3

    3,853View on GitHub↗

    Pocsuite3 is a modular vulnerability testing framework designed for the development and execution of security assessment scripts. It provides a comprehensive toolkit for remote vulnerability verification and exploitation, enabling users to automate the identification of security flaws across network targets. The framework is built on an object-oriented scripting architecture that allows for the creation of custom security modules and plugins. It distinguishes itself through a highly extensible design that supports asynchronous task execution for large-scale infrastructure assessments, alongsi

    Pythonpentestingpythonsecurity
    View on GitHub↗3,853
  • reverse-shell/routersploitreverse-shell avatar

    reverse-shell/routersploit

    13,151View on GitHub↗

    RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers

    Python
    View on GitHub↗13,151
  • k8gege/k8toolsk8gege avatar

    k8gege/K8tools

    6,167View on GitHub↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    PowerShell0daybrute-forcebypass
    View on GitHub↗6,167
  • joaomatosf/jexbossjoaomatosf avatar

    joaomatosf/jexboss

    2,512View on GitHub↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Pythondeserializationexploitexploiting-vulnerabilities
    View on GitHub↗2,512