
AMFDSer-ngng
A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

BurpSuite Standard/Private Collaborator Library

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

find sensitive data leaking from ServiceNow instances.

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Vulnerability Assessment Scanner with Report Generation

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Burp Extension for collaboration in Faraday

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Burp extension for wordpress security scanning

Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and…

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…