
faraday_burp
Burp Extension for collaboration in Faraday

Burp Extension for collaboration in Faraday

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

API Scraper Agent for Web API's

Burp extension for wordpress security scanning

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Alexa skill example for Faraday API

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…