
agent-opfor
Open-source adversary emulation for AI agents and MCP servers.

Open-source adversary emulation for AI agents and MCP servers.

The DevSecOps toolset for REST APIs

SSRF plugin for burp Automates SSRF Detection in all of the Request

An strace-like program for the Windows 'native' API

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

A coverage-guided REST API fuzzer developed on top of LibAFL

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

End to End testing of Web, API, Cloud, Events and Security

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions