
Extractor
Extension adds a new tab in Burp Suite called Extractor

Extension adds a new tab in Burp Suite called Extractor

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

Alexa skill example for Faraday API

Bambdas collection for Burp Suite Professional and Community.

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

Suite for reverse shell handling geared toward working within the native shell

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

Open-source MITM proxy to intercept, inspect, and mock network traffic.

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

API Scraper Agent for Web API's

Node.js SDK for capturing and replaying API calls made to/from your service

HTTP Proxy Analysis for reverse engineering protocol communication

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.