
ParamFinder
Discover hidden parameters in Caido

Discover hidden parameters in Caido

MAPS cloud scanner and response parser for Microsoft Defender research.

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

HTTP Proxy Analysis for reverse engineering protocol communication

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

find sensitive data leaking from ServiceNow instances.

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

API Scraper Agent for Web API's

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…