awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to mgeeky/burpcontextawarefuzzer

Open-source alternatives to BurpContextAwareFuzzer

30 open-source projects similar to mgeeky/burpcontextawarefuzzer, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best BurpContextAwareFuzzer alternative.

  • gosecure/burp-fuzzy-encoding-generatorGoSecure avatar

    GoSecure/burp-fuzzy-encoding-generator

    7View on GitHub↗

    Quickly test various encoding for a given value in Burp Intruder

    Kotlin
    View on GitHub↗7
  • ultimatehackers/xsstrikeUltimateHackers avatar

    UltimateHackers/XSStrike

    15,027View on GitHub↗

    XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.

    Python
    View on GitHub↗15,027
  • maurosoria/dirsearchmaurosoria avatar

    maurosoria/dirsearch

    14,403View on GitHub↗

    dirsearch is a command-line security tool and web path scanner used for discovering hidden directories and files on web servers. It functions as a recursive directory fuzzer and brute-force utility that identifies undocumented paths and sensitive files using wordlists and HTTP status codes. The tool distinguishes itself through template-driven path generation and an automated HTTP response filter that uses status codes, content length, and regex patterns to isolate valid targets. It supports recursive directory crawling to map complex web structures and provides state-persistence serializatio

    Python
    View on GitHub↗14,403
  • coreyd97/stepperCoreyD97 avatar

    CoreyD97/Stepper

    202View on GitHub↗

    A natural evolution of Burp Suite's Repeater tool

    Java
    View on GitHub↗202

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • d3vilbug/hackbard3vilbug avatar

    d3vilbug/HackBar

    1,627View on GitHub↗

    HackBar plugin for Burpsuite

    Java
    View on GitHub↗1,627
  • enablesecurity/burp-luhn-payload-processorEnableSecurity avatar

    EnableSecurity/burp-luhn-payload-processor

    12View on GitHub↗

    A plugin for Burp Suite Pro to work with attacker payloads and automatically generate check digits for credit card numbers and similar numbers that end with a check digit generated using the Luhn algorithm or formula (also known as the "modulus 10" or "mod 10" algorithm).

    Python
    View on GitHub↗12
  • floyd-fuh/burp-httpfuzzerfloyd-fuh avatar

    floyd-fuh/burp-httpfuzzer

    34View on GitHub↗

    A simple random HTTP fuzzer. This plugin adds ActiveScan checks that fuzz the HTTP request. Using this fuzzer with any standard HTTP server (Apache, Nginx, etc.) is usually useless, but can be fun. It can be used to see the different error conditions a server and the web application code can run…

    Python
    View on GitHub↗34
  • geoffwalton/burp--adhoc-payload-processorsGeoffWalton avatar

    GeoffWalton/burp--Adhoc-Payload-Processors

    4View on GitHub↗

    Generate payload processors on the fly - without having to create individual extensions.

    Ruby
    View on GitHub↗4
  • h3xstream/http-script-generatorh3xstream avatar

    h3xstream/http-script-generator

    301View on GitHub↗

    This extension generates scripts to reissue a selected request. The scripts can be run outside of Burp. It can be useful to script attacks such as second order SQL injection, padding oracle, fuzzing encoded value, etc.

    Java
    View on GitHub↗301
  • huvuqu/fuzz18plushuvuqu avatar

    huvuqu/fuzz18plus

    7View on GitHub↗

    Advance of fuzzing for Web pentest. Based on Burp extension, send HTTP request template out to Python fuzzer.

    Java
    View on GitHub↗7
  • ikkisoft/blazerikkisoft avatar

    ikkisoft/blazer

    49View on GitHub↗

    Burp Suite AMF Extension

    Java
    View on GitHub↗49
  • ikkisoft/bradamsaikkisoft avatar

    ikkisoft/bradamsa

    90View on GitHub↗

    Burp Suite extension to generate Intruder payloads using Radamsa

    Java
    View on GitHub↗90
  • infodel/burp.extension-payloadparserinfodel avatar

    infodel/burp.extension-payloadparser

    5View on GitHub↗

    Burp Extension for parsing payloads containing/excluding characters you provide.

    Python
    View on GitHub↗5
  • jgillam/burp-co2JGillam avatar

    JGillam/burp-co2

    153View on GitHub↗

    A collection of enhancements for Portswigger's popular Burp Suite web penetration testing tool.

    Java
    View on GitHub↗153
  • jiangsir404/xss-sql-fuzzjiangsir404 avatar

    jiangsir404/Xss-Sql-Fuzz

    63View on GitHub↗

    burpsuite 插件对GP所有参数(过滤特殊参数)一键自动添加xss sql payload 进行fuzz

    Python
    View on GitHub↗63
  • mseclab/burp-pyjfuzzmseclab avatar

    mseclab/burp-pyjfuzz

    56View on GitHub↗

    Burp Suite plugin which implement PyJFuzz for fuzzing web application.

    Python
    View on GitHub↗56
  • nscuro/bradamsa-ngnscuro avatar

    nscuro/bradamsa-ng

    21View on GitHub↗

    A Burp Suite extension for Radamsa-powered fuzzing with Intruder

    Java
    View on GitHub↗21
  • pinnace/burp-jwt-fuzzhelper-extensionpinnace avatar

    pinnace/burp-jwt-fuzzhelper-extension

    101View on GitHub↗

    JSON Web Token (JWT) support for Burp Intruder. This extension adds a payload processor for fuzzing JWT claims.

    Python
    View on GitHub↗101
  • portswigger/turbo-intruderPortSwigger avatar

    PortSwigger/turbo-intruder

    1,769View on GitHub↗

    Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.

    Kotlin
    View on GitHub↗1,769
  • quahac/burp-intruder-hashcat-maskprocessorquahac avatar

    quahac/burp-intruder-hashcat-maskprocessor

    20View on GitHub↗

    Burp Hashcat Maskprocessor Extension, inspired by hashcat maskprocessor https://github.com/hashcat/maskprocessor

    Python
    View on GitHub↗20
  • raz0r/burp-radamsaraz0r avatar

    raz0r/burp-radamsa

    23View on GitHub↗

    burp-radamsa

    View on GitHub↗23
  • redguard/sheet-intruderRedguard avatar

    Redguard/Sheet-Intruder

    4View on GitHub↗

    Enables transparent use of Excel files in Burp Suite

    Java
    View on GitHub↗4
  • righettod/virtualhost-payload-generatorrighettod avatar

    righettod/virtualhost-payload-generator

    61View on GitHub↗

    BURP extension providing a set of values for the HTTP request "Host" header for the "BURP Intruder" in order to abuse virtual host resolution.

    Java
    View on GitHub↗61
  • synacktiv/hoplasynacktiv avatar

    synacktiv/HopLa

    828View on GitHub↗

    HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

    Java
    View on GitHub↗828
  • team-firebugs/burp-lfi-testsTeam-Firebugs avatar

    Team-Firebugs/Burp-LFI-tests

    69View on GitHub↗

    Fuzzing for LFI using Burpsuite

    View on GitHub↗69
  • volkandindar/agarthavolkandindar avatar

    volkandindar/agartha

    399View on GitHub↗

    A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.

    Python
    View on GitHub↗399
  • wdahlenburg/logicalfuzzingenginewdahlenburg avatar

    wdahlenburg/LogicalFuzzingEngine

    11View on GitHub↗

    A Burpsuite extension written in Python to perform basic validation fuzzing

    Python
    View on GitHub↗11
  • anof-cyber/paraforgeAnof-cyber avatar

    Anof-cyber/ParaForge

    142View on GitHub↗

    A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

    Python
    View on GitHub↗142
  • xnl-h4ck3r/gap-burp-extensionxnl-h4ck3r avatar

    xnl-h4ck3r/GAP-Burp-Extension

    1,520View on GitHub↗

    Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist

    Python
    View on GitHub↗1,520
  • bit4woo/recaptchabit4woo avatar

    bit4woo/reCAPTCHA

    810View on GitHub↗

    reCAPTCHA = REcognize CAPTCHA: A Burp Suite Extender that recognize CAPTCHA and use for intruder payload 自动识别图形验证码并用于burp intruder爆破模块的插件

    Java
    View on GitHub↗810