
Mass-Assigner
Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Hackable HTTP proxy for resiliency testing and simulated network conditions

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Automated HTTP Request Repeating With Burp Suite

a Damn Vulnerable Serverless Application

SAML2 Burp Extension

Research on GraphQL from an AppSec point of view.

PyJFuzz - Python JSON Fuzzer

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

Hidden parameters discovery suite

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Python PoC validating unauthenticated BookingPress Pro REST API exposure and checking for exposed booking/customer data with configurable request…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

MAPS cloud scanner and response parser for Microsoft Defender research.

Damn Vulnerable C# Application (API)

POC for Veeam Backup and Replication CVE-2023-27532

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.