
ParamFinder
Discover hidden parameters in Caido

Discover hidden parameters in Caido

Burp Commander written in Go

This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, Proxy…

An HTTP client specifically developed for security researchers

Radamsa fuzzer extension for Burp Suite

BurpSuite Standard/Private Collaborator Library

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

API Scraper Agent for Web API's

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

OAuth Request Crafter

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

Alexa skill example for Faraday API

A proxy for net.tcp-based WCF traffic.

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…