awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to doyensec/inql

Projects sharing features with Inql

30 open-source projects similar to doyensec/inql, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • dolevf/graphql-copdolevf avatar

    dolevf/graphql-cop

    652View on GitHub↗

    Security Auditor Utility for GraphQL APIs

    Python
    View on GitHub↗652
  • nikitastupin/clairvoyancenikitastupin avatar

    nikitastupin/clairvoyance

    1,481View on GitHub↗

    Obtain GraphQL API schema even if the introspection is disabled

    Python
    View on GitHub↗1,481
  • swisskyrepo/graphqlmapswisskyrepo avatar

    swisskyrepo/GraphQLmap

    1,670View on GitHub↗

    GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

    Python
    View on GitHub↗1,670
  • aquasecurity/trivyaquasecurity avatar

    aquasecurity/trivy

    36,462View on GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    View on GitHub↗36,462
  • assetnote/batchqlassetnote avatar

    assetnote/batchql

    412View on GitHub↗

    GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

    Python
    View on GitHub↗412

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • portswigger/collaborator-everywherePortSwigger avatar

    PortSwigger/collaborator-everywhere

    447View on GitHub↗

    A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal backend systems by causing pingbacks to Burp Collaborator

    Java
    View on GitHub↗447
  • h3xstream/burp-retire-jsh3xstream avatar

    h3xstream/burp-retire-js

    213View on GitHub↗

    Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.

    JavaScript
    View on GitHub↗213
  • escape-technologies/graphinderEscape-Technologies avatar

    Escape-Technologies/graphinder

    228View on GitHub↗

    🕸️ Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce. 🕸️

    Python
    View on GitHub↗228
  • portswigger/http-request-smugglerportswigger avatar

    portswigger/http-request-smuggler

    1,213View on GitHub↗

    This Burp Suite extension automatically detects and exploits HTTP Request Smuggling vulnerabilities using advanced desynchronization techniques developed by PortSwigger researcher James Kettle. It supports comprehensive scanning for HTTP/1.1 and HTTP/2-downgrade desync vulnerabilities,…

    Java
    View on GitHub↗1,213
  • s0md3v/xsstrikes0md3v avatar

    s0md3v/XSStrike

    14,752View on GitHub↗

    XSStrike is an automated security scanning engine designed for web application discovery, input

    Pythonwaf-detectionxssxss-bruteforce
    View on GitHub↗14,752
  • secdec/attack-surface-detector-burpsecdec avatar

    secdec/attack-surface-detector-burp

    113View on GitHub↗

    The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters

    Java
    View on GitHub↗113
  • wagiro/burpbountywagiro avatar

    wagiro/BurpBounty

    1,806View on GitHub↗

    Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.

    Java
    View on GitHub↗1,806
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Goattack-surfacecve-scannerdast
    View on GitHub↗29,189
  • presidentbeef/brakemanpresidentbeef avatar

    presidentbeef/brakeman

    7,248View on GitHub↗

    Brakeman is a static analysis security tool and scanner specifically designed for Ruby on Rails source code. It identifies common security vulnerabilities, such as injection and cross-site scripting, by analyzing the application codebase without executing the application. The tool functions as a security auditor that detects mass assignment risks and template vulnerabilities. It evaluates the final output of rendered views and identifies unrestricted assignment patterns that could allow unauthorized modification of model attributes. The system provides vulnerability management through the us

    Ruby
    View on GitHub↗7,248
  • gosecure/csp-auditorGoSecure avatar

    GoSecure/csp-auditor

    142View on GitHub↗

    Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website

    Java
    View on GitHub↗142
  • dstotijn/hettydstotijn avatar

    dstotijn/hetty

    11,485View on GitHub↗

    Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic between a browser and a server. It functions as an HTTP request editor for creating and replaying manual requests to test server behavior and as a project-based traffic logger that isolates network logs across different security research engagements. The tool provides a request-response interception loop that pauses outgoing requests and incoming responses in transit, allowing for manual editing or cancellation. It includes a manual request replay engine to construct and transmit

    Go
    View on GitHub↗11,485
  • reverse-shell/routersploitreverse-shell avatar

    reverse-shell/routersploit

    13,151View on GitHub↗

    RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers

    Python
    View on GitHub↗13,151
  • joaomatosf/jexbossjoaomatosf avatar

    joaomatosf/jexboss

    2,512View on GitHub↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Pythondeserializationexploitexploiting-vulnerabilities
    View on GitHub↗2,512
  • ah8r/csrfah8r avatar

    ah8r/csrf

    20View on GitHub↗

    CSRF Scanner Extension for Burp Suite Pro

    Java
    View on GitHub↗20
  • antx-code/cve-2022-21907A

    antx-code/CVE-2022-21907

    0View on GitHub↗
    View on GitHub↗0
  • 0xanuj/blinks0xanuj avatar

    0xanuj/blinks

    143View on GitHub↗

    Blinks is a powerful Burp Suite extension that automates active scanning with Burp Suite Pro and enhances its functionality. With the integration of webhooks, this tool sends real-time updates whenever a new issue is identified, directly to your preferred endpoint. No more waiting for final reports – you get instant, actionable insights! 🛠️

    Python
    View on GitHub↗143
  • anshumanpattnaik/http-request-smugglinganshumanpattnaik avatar

    anshumanpattnaik/http-request-smuggling

    539View on GitHub↗

    HTTP Request Smuggling Detection Tool

    Python
    View on GitHub↗539
  • artssec/burp-exporterA

    artssec/burp-exporter

    0View on GitHub↗
    View on GitHub↗0
  • arpsyndicate/kenzerA

    ARPSyndicate/kenzer

    0View on GitHub↗
    View on GitHub↗0
  • andresriancho/w3afandresriancho avatar

    andresriancho/w3af

    4,850View on GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    View on GitHub↗4,850
  • assetnote/h2csmugglerA

    assetnote/h2csmuggler

    0View on GitHub↗
    View on GitHub↗0
  • augustd/burp-suite-error-message-checksaugustd avatar

    augustd/burp-suite-error-message-checks

    65View on GitHub↗

    Burp Suite extension to passively scan for applications revealing server error messages

    Java
    View on GitHub↗65
  • augustd/burp-suite-gwt-scanaugustd avatar

    augustd/burp-suite-gwt-scan

    13View on GitHub↗

    Burp Suite plugin identifies insertion points for GWT (Google Web Toolkit) requests

    Java
    View on GitHub↗13
  • augustd/burp-suite-software-version-checksaugustd avatar

    augustd/burp-suite-software-version-checks

    33View on GitHub↗

    Burp extension to passively scan for applications revealing software version numbers

    Java
    View on GitHub↗33
  • acheron-vaf/acheronA

    Acheron-VAF/Acheron

    0View on GitHub↗
    View on GitHub↗0