
sj
A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Automated HTTP Request Repeating With Burp Suite

A wordlist of API names for web application assessments

The AI toolkit for building reliable browser automations

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

Tests your WAF with +160 payloads

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

PyJFuzz - Python JSON Fuzzer

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

An intentionally designed broken web application based on REST API.

SSRF plugin for burp Automates SSRF Detection in all of the Request

An strace-like program for the Windows 'native' API


Burp Plugin to decrypt AES encrypted traffic on the fly

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.