awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to secdec/attack-surface-detector-burp

Open-source alternatives to Attack Surface Detector Burp

30 open-source projects similar to secdec/attack-surface-detector-burp, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Attack Surface Detector Burp alternative.

  • portswigger/collaborator-everywherePortSwigger avatar

    PortSwigger/collaborator-everywhere

    447View on GitHub↗

    A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal backend systems by causing pingbacks to Burp Collaborator

    Java
    View on GitHub↗447
  • portswigger/http-request-smugglerportswigger avatar

    portswigger/http-request-smuggler

    1,213View on GitHub↗

    This Burp Suite extension automatically detects and exploits HTTP Request Smuggling vulnerabilities using advanced desynchronization techniques developed by PortSwigger researcher James Kettle. It supports comprehensive scanning for HTTP/1.1 and HTTP/2-downgrade desync vulnerabilities,…

    Java
    View on GitHub↗1,213
  • silentsignal/burp-image-sizesilentsignal avatar

    silentsignal/burp-image-size

    95View on GitHub↗

    Image size issues plugin for Burp Suite

    Java
    View on GitHub↗95
  • pmiaowu/burpshiropassivescanpmiaowu avatar

    pmiaowu/BurpShiroPassiveScan

    1,802View on GitHub↗

    一款基于BurpSuite的被动式shiro检测插件

    Java
    View on GitHub↗1,802
  • prodigysml/dr.-watsonprodigysml avatar

    prodigysml/Dr.-Watson

    217View on GitHub↗

    Dr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful information! It's your very own discovery side kick, the Dr. Watson to your Sherlock!

    Python
    View on GitHub↗217

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • solomonsklash/sri-checkSolomonSklash avatar

    SolomonSklash/sri-check

    13View on GitHub↗

    A Burp Suite extension for identifying missing Subresource Integrity attributes.

    Python
    View on GitHub↗13
  • codingo/minesweepercodingo avatar

    codingo/Minesweeper

    203View on GitHub↗

    A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

    Python
    View on GitHub↗203
  • augustd/burp-suite-gwt-scanaugustd avatar

    augustd/burp-suite-gwt-scan

    13View on GitHub↗

    Burp Suite plugin identifies insertion points for GWT (Google Web Toolkit) requests

    Java
    View on GitHub↗13
  • h3xstream/burp-retire-jsh3xstream avatar

    h3xstream/burp-retire-js

    213View on GitHub↗

    Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.

    JavaScript
    View on GitHub↗213
  • nccgroup/blackboxprotobufnccgroup avatar

    nccgroup/blackboxprotobuf

    730View on GitHub↗

    Blackbox Protobuf now has an official package on PyPi under the name bbpb. The blackboxprotobuf package is an older fork

    Python
    View on GitHub↗730
  • bugcrowd/huntbugcrowd avatar

    bugcrowd/HUNT

    2,321View on GitHub↗

    HUNT Suite is a collection of Burp Suite Pro/Free and OWASP ZAP extensions. Identifies common parameters vulnerable to certain vulnerability classes (Burp Suite Pro and OWASP ZAP). Organize testing methodologies (Burp Suite Pro and Free).

    Python
    View on GitHub↗2,321
  • snoopysecurity/noopener-burp-extensionsnoopysecurity avatar

    snoopysecurity/Noopener-Burp-Extension

    5View on GitHub↗

    Find Target="_blank" values within web pages that are set without 'noopener' and 'noreferrer' attributes

    Python
    View on GitHub↗5
  • yandex/burp-molly-packyandex avatar

    yandex/burp-molly-pack

    140View on GitHub↗

    Security checks pack for Burp Suite

    Java
    View on GitHub↗140
  • xnl-h4ck3r/gap-burp-extensionxnl-h4ck3r avatar

    xnl-h4ck3r/GAP-Burp-Extension

    1,520View on GitHub↗

    Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist

    Python
    View on GitHub↗1,520
  • dobin/burpsentineldobin avatar

    dobin/BurpSentinel

    153View on GitHub↗

    GUI Burp Plugin to ease discovering of security holes in web applications

    Java
    View on GitHub↗153
  • bit4woo/knifebit4woo avatar

    bit4woo/knife

    1,937View on GitHub↗

    A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅

    Javaburpburp-extensionsburp-plugin
    View on GitHub↗1,937
  • bytebutcher/burp-send-tobytebutcher avatar

    bytebutcher/burp-send-to

    169View on GitHub↗

    Adds a customizable "Send to..."-context-menu to your BurpSuite.

    Java
    View on GitHub↗169
  • cnotin/burp-scan-manual-insertion-pointcnotin avatar

    cnotin/burp-scan-manual-insertion-point

    11View on GitHub↗

    Burp Suite Pro extension

    Java
    View on GitHub↗11
  • doyensec/inqldoyensec avatar

    doyensec/inql

    1,782View on GitHub↗

    InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

    Kotlin
    View on GitHub↗1,782
  • gosecure/csp-auditorGoSecure avatar

    GoSecure/csp-auditor

    142View on GitHub↗

    Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website

    Java
    View on GitHub↗142
  • ilmila/j2eescanilmila avatar

    ilmila/J2EEScan

    677View on GitHub↗

    J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tests on J2EE applications.

    Java
    View on GitHub↗677
  • moloch--/csp-bypassmoloch-- avatar

    moloch--/CSP-Bypass

    167View on GitHub↗

    A Burp Plugin for Detecting Weaknesses in Content Security Policies

    Python
    View on GitHub↗167
  • silentsignal/burp-uuidsilentsignal avatar

    silentsignal/burp-uuid

    55View on GitHub↗

    UUID issues for Burp Suite

    Java
    View on GitHub↗55
  • reverse-shell/routersploitreverse-shell avatar

    reverse-shell/routersploit

    13,151View on GitHub↗

    RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers

    Python
    View on GitHub↗13,151
  • joaomatosf/jexbossjoaomatosf avatar

    joaomatosf/jexboss

    2,512View on GitHub↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Pythondeserializationexploitexploiting-vulnerabilities
    View on GitHub↗2,512
  • allfro/dotnetbeautifierallfro avatar

    allfro/dotNetBeautifier

    12View on GitHub↗

    A BurpSuite extension for beautifying .NET message parameters and hiding some of the extra clutter that comes with .NET web apps (i.e. VIEWSTATE).

    Java
    View on GitHub↗12
  • aress31/swurgAresS31 avatar

    AresS31/swurg

    208View on GitHub↗

    Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their official BApp Store).

    Java
    View on GitHub↗208
  • aress31/googleauthenticatoraress31 avatar

    aress31/googleauthenticator

    30View on GitHub↗

    This Burp Suite extension turns Burp into a Google Authenticator client. The current Google Two-Factor Authentication (2FA) code is automatically computed from a given shared secret and applied to bespoke location(s) in relevant requests in real-time.

    Java
    View on GitHub↗30
  • arinerron/cve-2022-0847-dirtypipe-exploitArinerron avatar

    Arinerron/CVE-2022-0847-DirtyPipe-Exploit

    1,128View on GitHub↗

    A root exploit for CVE-2022-0847 (Dirty Pipe)

    C
    View on GitHub↗1,128
  • allfro/burpkitallfro avatar

    allfro/BurpKit

    461View on GitHub↗

    Next-gen BurpSuite penetration testing tool

    JavaScript
    View on GitHub↗461