
raider
DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

A rapid HTTP downgrade smuggling scanner written in Go.

A Burp Extension designed to identify argument injection vulnerabilities.


Hermes Proxy - HTTP Traffic Analyzer

A program for testing WAF functionality

HTTP Proxy Analysis for reverse engineering protocol communication

find sensitive data leaking from ServiceNow instances.

Vulnerability Assessment Scanner with Report Generation


API Scraper Agent for Web API's

Burp extension for wordpress security scanning

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

Apache Text4Shell (CVE-2022-42889) Burp Bounty Profile