
waf-checker
Tests your WAF with +160 payloads

Tests your WAF with +160 payloads

a Damn Vulnerable Serverless Application

An intentionally designed broken web application based on REST API.

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Official Elastic Skills

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

WEB SERVICE SECURITY ASSESSMENT TOOL

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Hidden parameters discovery suite

Automated testing suite with live traffic record and replay

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977