
cherrybomb
CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

Burp Plugin to decrypt AES encrypted traffic on the fly

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations


This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

End to End testing of Web, API, Cloud, Events and Security

Hidden parameters discovery suite

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

The collaborative web app pentest suite

Discover hidden parameters in Caido

Performing automated scan using Burp Suite Pro & Vmware Burp Rest API

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.