
nuclei-burp-plugin
Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Research on GraphQL from an AppSec point of view.

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

Python API security testing tool from OpenStack Security Group

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

The collaborative web app pentest suite

Burp Commander written in Go



find sensitive data leaking from ServiceNow instances.

Burp Extension for collaboration in Faraday

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.