
HTTPSignatures
A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

SAML2 Burp Extension

SAML2 Burp Extension

Improved decoder for Burp Suite

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

A comprehensive, step-by-step guide to mastering cybersecurity from beginner to expert level with curated resources, tools, and career guidance

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

Trail of Bits Testing Handbook - appsec.guide

A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish…

Exploit for cryptographic Issue vulnerability on IBERMATICA RPS [CVE-2023-3350]

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

Ruby client for the Qualys SSL Labs API enabling automated SSL/TLS server assessment, vulnerability detection (e.g., BEAST), and security grade…

A curated list of CTF frameworks, libraries, resources and softwares