
jsluicepp
jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Hidden parameters discovery suite

A rapid HTTP downgrade smuggling scanner written in Go.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

⚡️ Multiple target ZAP Scanning

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Rust-powered HTTP Request Smuggling Scanner.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

A Burp Extension designed to identify argument injection vulnerabilities.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Ruby command-line interface to Burp Suite's REST API

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…