
sqlipy
SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Rust-powered HTTP Request Smuggling Scanner.

A rapid HTTP downgrade smuggling scanner written in Go.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Damn Vulnerable C# Application (API)

⚡️ Multiple target ZAP Scanning

A Burp Extension designed to identify argument injection vulnerabilities.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Ruby command-line interface to Burp Suite's REST API

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…