
GraphCrawler
GraphQL automated security testing toolkit

GraphQL automated security testing toolkit

ExtendedMacro - BurpSuite plugin providing extended macro functionality

A modern vulnerable web app

CLI component of purpleteam

Web app authorisation coverage scanning

Python API security testing tool from OpenStack Security Group

Server scanning component of purpleteam

API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…

Sample Burp Suite extensions demonstrating the Montoya API, covering HTTP and proxy handlers, custom scan checks, Intruder payloads, WebSocket…

Burp Suite extension that uses AI-generated regex strike rules to detect IDOR and access-control flaws, then scans proxy history to find similar…

Burp Suite Repeater extension that automatically mutates payloads and analyzes responses to uncover path traversal, SQL injection, XSS, and other web…

Burp Suite extension that extends active and passive scanning with checks for host header attacks, XXE, code injection, and known CVEs like…

Burp Suite extension for fuzzing WebSocket messages with custom Python code, supporting multiple engines, HTTP middleware routing, and response…

XML Signature Wrapping Burp Suite Extensions