
bug-reaper
Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, Proxy…

A Burp Extender plugin, that will make binary soap objects readable and modifiable.

An HTTP client specifically developed for security researchers

CyberArk Security Audit

Radamsa fuzzer extension for Burp Suite

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

BurpSuite Standard/Private Collaborator Library

HTTP Proxy Analysis for reverse engineering protocol communication

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

find sensitive data leaking from ServiceNow instances.

An API hooking framework for intercepting and monitoring Windows applications

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Vulnerability Assessment Scanner with Report Generation

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.