
AutoNessus
This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, Proxy…

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

This script exploits the CVE-2024-40094 vulnerability in graphql-java

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A fast, simple, recursive content discovery tool written in Rust.

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

An intentionally designed broken web application based on REST API.

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

Threat Hunting tool about Sysmon and graphs

SSRF plugin for burp Automates SSRF Detection in all of the Request

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

CVE-2026-9830 Proof of Concept