
oproxy
Open-source MITM proxy to intercept, inspect, and mock network traffic.

Open-source MITM proxy to intercept, inspect, and mock network traffic.

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

SAML2 Burp Extension

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

WEB SERVICE SECURITY ASSESSMENT TOOL

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Hidden parameters discovery suite

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Rust-powered HTTP Request Smuggling Scanner.

A rapid HTTP downgrade smuggling scanner written in Go.

⚡️ Multiple target ZAP Scanning

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

A Burp Extension designed to identify argument injection vulnerabilities.