
BurpAPISecuritySuite
Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Collaborative application security testing between humans and agents via CLI and MCP

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

Testing

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

Proof-of-concept HTML page that reproduces CVE-2019-10070, a cross-site scripting vulnerability in Apache Atlas, for validation and defensive testing.

SAML2 Burp Extension

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Professional extension of sqlmap project

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…