
sj
A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Tests your WAF with +160 payloads

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

SAML2 Burp Extension

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

PyJFuzz - Python JSON Fuzzer

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Open-source MITM proxy to intercept, inspect, and mock network traffic.

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

SSRF plugin for burp Automates SSRF Detection in all of the Request

WEB SERVICE SECURITY ASSESSMENT TOOL


jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.