
OAuth-Request-Crafter
OAuth Request Crafter

OAuth Request Crafter

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

An on-path blackbox network traffic security testing tool

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

Hidden parameters discovery suite

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

REST/JSON API to the Burp Suite security tool.


A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

WEB SERVICE SECURITY ASSESSMENT TOOL

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and…