
waf-bypass
Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Go client to communicate with Chaos DB API.

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Automated HTTP Request Repeating With Burp Suite

A wordlist of API names for web application assessments

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

A fast WordPress plugin enumeration tool

PyJFuzz - Python JSON Fuzzer

The AI toolkit for building reliable browser automations

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

An intentionally designed broken web application based on REST API.

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Tests your WAF with +160 payloads