
AMFDSer-ngng
A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

Windows named pipe hooking toolkit


BurpSuite Standard/Private Collaborator Library

Radamsa fuzzer extension for Burp Suite

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Agent-based JMX access via JSON/HTTP with bulk requests, fine-grained security policies, and proxy mode for remote MBeanServer monitoring and…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

The collaborative web app pentest suite

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

An API hooking framework for intercepting and monitoring Windows applications

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A Burp Suite extension that integrates Dalfox XSS scanner directly into your workflow.

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …