
http-desync-guardian
Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

SSRF plugin for burp Automates SSRF Detection in all of the Request

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

CVE-2026-9830 Proof of Concept

WEB SERVICE SECURITY ASSESSMENT TOOL

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Hidden parameters discovery suite

A rapid HTTP downgrade smuggling scanner written in Go.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

⚡️ Multiple target ZAP Scanning

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Rust-powered HTTP Request Smuggling Scanner.