
AMFDSer-ngng
A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava


BurpSuite Standard/Private Collaborator Library

Radamsa fuzzer extension for Burp Suite

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

An API hooking framework for intercepting and monitoring Windows applications

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

MAPS cloud scanner and response parser for Microsoft Defender research.

Hermes Proxy - HTTP Traffic Analyzer

Automated testing suite with live traffic record and replay

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…