
BurpCrypto
BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

Template-driven reflected XSS scanner that generates obfuscated, unique payloads to evade detection, with support for custom headers, proxy, polyglot…

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…

ARM64 ELF Virtual Machine Protection System

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Automated XXE exploitation tool that generates XML payloads, serves DTDs, and performs data exfiltration with support for OOB, CDATA, fuzzing, and…

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

ZIP File Raider - Burp Extension for ZIP File Payload Testing

A Python3 module to assist in fuzzing web applications

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…

Proof-of-concept generator for CVE-2026-14266, a heap buffer overflow in 7-Zip's XZ decoder. Creates crafted .xz archives to reproduce the crash…

Generic Scanner for Apache log4j RCE CVE-2021-44228

Reproduces aiohttp CWE-444 request smuggling via rejected WebSocket upgrades, with Python/Rust payloads and Docker lab demonstrating proxy…

Lightweight scanner and Nuclei templates for identifying React and Next.js deserialization RCEs (CVE-2025-55182 / CVE-2025-66478).