
rep-chrome
rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Burp Plugin for Secret Matching

Passive recon & attack surface mapper — zero requests sent

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Vulnerability Assessment Scanner with Report Generation

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

A CVE-2025-55183 secret miner

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

Notes about attacking Jenkins servers