
x8-Burp
Hidden parameters discovery suite

Hidden parameters discovery suite

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Node.js SDK for capturing and replaying API calls made to/from your service

Automated testing suite with live traffic record and replay

Hermes Proxy - HTTP Traffic Analyzer

Discover hidden parameters in Caido

Burp Commander written in Go

This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, Proxy…

An HTTP client specifically developed for security researchers

Radamsa fuzzer extension for Burp Suite

BurpSuite Standard/Private Collaborator Library

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

API Scraper Agent for Web API's

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.