Home

Awesome

<h1 align="center"> <br> <a href=""><img src="https://user-images.githubusercontent.com/13212227/104400969-9f3d9280-5596-11eb-80f4-864effae95fc.png" alt="" width="500px;"></a> <br> <img src="https://img.shields.io/github/last-commit/hahwul/WebHackersWeapons?style=flat"> <img src="https://img.shields.io/badge/PRs-welcome-cyan"> <img src="https://github.com/hahwul/WebHackersWeapons/actions/workflows/cd.yml/badge.svg"> <a href="https://twitter.com/intent/follow?screen_name=hahwul"><img src="https://img.shields.io/twitter/follow/hahwul?style=flat&logo=twitter"></a> </h1> A collection of awesome tools used by Web hackers. Happy hacking , Happy bug-hunting

Family project

WebHackersWeapons MobileHackersWeapons

Table of Contents

Weapons

Attributes

Attributes
TypesArmy-Knife Proxy Recon Fuzzer Scanner Exploit Env Utils Etc
Tagsinfra pentest crawl recon exploit mitmproxy live-audit subdomains apk url endpoint osint param portscan takeover dns favicon js-analysis port csp attack-surface domain online graphql path-traversal ssrf cache-vuln smuggle fuzz ssti jwt crlf prototypepollution prototype-pollution header ssl aaa xss nosqli 403 dependency-confusion cors s3 sqli oast broken-link lfi rfi xxe rop RMI http cookie report nuclei-templates zipbomb web3 note wordlist documents browser-record blind-xss gRPC-Web encode darkmode deserialize diff json notify dom payload clipboard
LangsShell Ruby Java Go Python Rust Kotlin C JavaScript Crystal Perl C# TypeScript HTML C++ Txt CSS PHP BlitzBasic

Tools

TypeNameDescriptionStarTagsBadges
Army-KnifeaxiomA dynamic infrastructure toolkit for red teamers and bug bounty hunters!infralinuxmacoswindowsShell
Army-KnifeMetasploitThe world’s most used penetration testing frameworkpentestlinuxmacoswindowsRuby
Army-knifeRoninFree and Open Source Ruby Toolkit for Security Research and Developmentpentest crawl recon exploitlinuxmacoswindowsRuby
Army-KnifeBurpSuiteThe BurpSuite Projectmitmproxy live-audit crawllinuxmacoswindowsburpJava
Army-KnifejaelesThe Swiss Army knife for automated Web Application Testinglive-auditlinuxmacoswindowsGo
Army-KnifeZAPThe ZAP core projectmitmproxy live-audit crawllinuxmacoswindowszapJava
ProxymitmproxyAn interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.mitmproxylinuxmacoswindowsPython
ProxyhettyHetty is an HTTP toolkit for security research. It aims to become an open source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug bounty community.mitmproxylinuxmacoswindowsGo
ProxyCaidoA lightweight web security auditing toolkitmitmproxylinuxmacoswindowscaidoRust
ProxyEcho MirageA generic network proxy that uses DLL injection to capture and alter TCP traffic.mitmproxywindows
ProxyGlorpA CLI-based HTTP intercept and replay proxymitmproxylinuxmacoswindowsGo
ProxyEvilProxyA ruby http/https proxy to do EVIL things.mitmproxylinuxmacoswindowsRuby
ProxyproxifySwiss Army knife Proxy tool for HTTP/HTTPS traffic capture, manipulation and replaymitmproxylinuxmacoswindowsGo
ReconBugBountyScannerA Bash script and Docker image for Bug Bounty reconnaissance.linuxmacoswindowsShell
ReconassetfinderFind domains and subdomains related to a given domainsubdomainslinuxmacoswindowsGo
ReconFavFreakMaking Favicon.ico based Recon Great again !linuxmacoswindowsPython
ReconhakrawlerSimple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web applicationcrawllinuxmacoswindowsGo
ReconapkleaksScanning APK file for URIs, endpoints & secrets.apk url endpointlinuxmacoswindowsPython
Recongoverviewgoverview - Get an overview of the list of URLsurllinuxmacoswindowsGo
Reconpagodopagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searchinglinuxmacoswindowsPython
ReconcrawlergoA powerful browser crawler for web vulnerability scannerscrawllinuxmacoswindowsGo
ReconbbotOSINT automation for hackersosintlinuxmacoswindowsPython
ReconParthHeuristic Vulnerable Parameter ScannerparamlinuxmacoswindowsPython
Recongowitness🔍 gowitness - a golang, web screenshot utility using Chrome HeadlesslinuxmacoswindowsGo
RecongospiderGospider - Fast web spider written in GocrawllinuxmacoswindowsGo
ReconPhotonIncredibly fast crawler designed for OSINT.osint crawllinuxmacoswindowsPython
Reconhttpxhttpx is a fast and multi-purpose HTTP toolkit allow to run multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads.urllinuxmacoswindowsGo
ReconmasscanTCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.portscanlinuxmacoswindowsC
ReconmegFetch many paths for many hosts - without killing the hostslinuxmacoswindowsGo
Reconrecon_profileRecon profile (bash profile) for bugbountylinuxmacoswindowsShell
ReconuncoverQuickly discover exposed hosts on the internet using multiple search engine.linuxmacoswindowsGo
ReconknockKnock Subdomain ScansubdomainslinuxmacoswindowsPython
ReconGitMinerTool for advanced mining for content on GithublinuxmacoswindowsPython
ReconsubgenA really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver!subdomainslinuxmacoswindowsGo
ReconSub404A python tool to check subdomain takeover vulnerabilitysubdomains takeoverlinuxmacoswindowsGo
ReconaltdnsGenerates permutations, alterations and mutations of subdomains and then resolves themdns subdomainslinuxmacoswindowsPython
Reconintrigue-coreDiscover Your Attack SurfacelinuxmacoswindowsRuby
ReconParamWizardParamWizard is a powerful Python-based tool designed for extracting and identifying URLs with parameters from a specified website.paramlinuxmacoswindowsPython
ReconshufflednsshuffleDNS is a wrapper around massdns written in go that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard handling and easy input-output support.dnslinuxmacoswindowsGo
ReconkatanaA next-generation crawling and spidering framework.crawllinuxmacoswindowsGo
ReconChaos Webactively scan and maintain internet-wide assets' data. enhance research and analyse changes around DNS for better insights.linuxmacoswindows
RecongauplusA modified version of gau for personal usage. Support workers, proxies and some extra things.urllinuxmacoswindowsGo
ReconOneForAllOneForAll是一款功能强大的子域收集工具linuxmacoswindowsPython
ReconSubOverA Powerful Subdomain Takeover Toolsubdomains takeoverlinuxmacoswindowsGo
ReconfindomainThe fastest and cross-platform subdomain enumerator, do not waste your time.subdomainslinuxmacoswindowsRust
Reconurodeclutters url lists for crawling/pentestingurllinuxmacoswindowsPython
ReconBLUTODNS Analysis TooldnslinuxmacoswindowsPython
ReconrusolverFast and accurate DNS resolver.dnslinuxmacoswindowsRust
Recongithub-endpointsFind endpoints on GitHub.linuxmacoswindowsGo
ReconfavireconUse favicon.ico to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.faviconlinuxmacoswindowsGo
ReconwaybackurlsFetch all the URLs that the Wayback Machine knows about for a domainurllinuxmacoswindowsGo
Reconscilla🏴‍☠️ Information Gathering tool 🏴‍☠️ dns/subdomain/port enumerationsubdomains dns portlinuxmacoswindowsGo
Reconchaos-clientGo client to communicate with Chaos DNS API.linuxmacoswindowsGo
ReconspiderfootSpiderFoot automates OSINT collection so that you can focus on analysis.osintlinuxmacoswindowsPython
ReconParamSpiderMining parameters from dark corners of Web ArchivesparamlinuxmacoswindowsPython
ReconSilverMass scan IPs for vulnerable servicesportlinuxmacoswindowsPython
ReconSecretFinderSecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript fileslinuxmacoswindowsPython
ReconpurednsPuredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.subdomains dnslinuxmacoswindowsGo
ReconcspreconDiscover new target domains using Content Security PolicycsplinuxmacoswindowsGo
Reconsubs_allSubdomain Enumeration Wordlist. 8956437 unique words. Updated.subdomainslinuxmacoswindows
RecondirsearchWeb path scannerlinuxmacoswindowsPython
ReconhtcatParallel and Pipelined HTTP GET UtilitylinuxmacoswindowsGo
ReconmegplusAutomated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]linuxmacoswindowsShell
ReconLinkFinderA python script that finds endpoints in JavaScript filesjs-analysislinuxmacoswindowsPython
RecondnsvalidatorMaintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.dnslinuxmacoswindowsPython
ReconHunt3rMade your bugbounty subdomains reconnaissance easier with Hunt3r the web application reconnaissance frameworklinuxmacoswindowsRuby
ReconSubBrutehttps://github.com/TheRook/subbrutesubdomainslinuxmacoswindowsPython
Recon3klConAutomation Recon tool which works with Large & Medium scopes. It performs more than 20 tasks and gets back all the results in separated files.linuxmacoswindowsPython
ReconaquatoneA Tool for Domain FlyoversdomainlinuxmacoswindowsGo
ReconsubjsFetches javascript file from a list of URLS or subdomains.url subdomainslinuxmacoswindowsGo
RecondmutA tool to perform permutations, mutations and alteration of subdomains in golang.subdomainslinuxmacoswindowsGo
ReconSecurityTrailsOnline dns / subdomain / recon toolsubdomains onlinelinuxmacoswindows
ReconcariddiTake a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and morecrawllinuxmacoswindowsGo
ReconSublist3rFast subdomains enumeration tool for penetration testerssubdomainslinuxmacoswindowsPython
ReconjsluiceExtract URLs, paths, secrets, and other interesting bits from JavaScriptjs-analysislinuxmacoswindowsGo
ReconnoirAttack surface detector that identifies endpoints by static analysisendpoint url attack-surfacelinuxmacosCrystal
ReconOsmedeusFully automated offensive security framework for reconnaissance and vulnerability scanninglinuxmacoswindowsGo
ReconArjunHTTP parameter discovery suite.paramlinuxmacoswindowsPython
ReconRustScanFaster Nmap Scanning with RustportscanlinuxmacoswindowsRust
ReconDNSDumpsterOnline dns recon & research, find & lookup dns recordsdns onlinelinuxmacoswindows
ReconrenginereNgine is an automated reconnaissance framework meant for gathering information during penetration testing of web applications. reNgine has customizable scan engines, which can be used to scan the websites, endpoints, and gather information.linuxmacoswindowsJavaScript
Reconsn0intSemi-automatic OSINT framework and package managerosintlinuxmacoswindowsRust
ReconhaktrailsGolang client for querying SecurityTrails API datalinuxmacoswindowsGo
ReconSudomysubdomain enumeration tool to collect subdomains and analyzing domainssubdomainslinuxmacoswindowsShell
ReconparamethThis tool can be used to brute discover GET and POST parameterslinuxmacoswindowsPython
ReconSmapa drop-in replacement for Nmap powered by shodan.ioportlinuxmacoswindowsGo
ReconnaabuA fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentestsportscanlinuxmacoswindowsGo
ReconshosubgoSmall tool to Grab subdomains using Shodan api.subdomainslinuxmacoswindowsGo
Recongraphw00fGraphQL Server Engine Fingerprinting utilitygraphqllinuxmacoswindowsPython
ReconsubjackSubdomain Takeover tool written in Gosubdomains takeoverlinuxmacoswindowsGo
Reconcc.pyExtracting URLs of a specific target based on the results of "commoncrawl.org"urllinuxmacoswindowsPython
Reconurlhuntera recon tool that allows searching on URLs that are exposed via shortener servicesurllinuxmacoswindowsGo
ReconShodanWorld's first search engine for Internet-connected devicesosintlinuxmacoswindows
ReconlongtongueCustomized Password/Passphrase List inputting Target InfolinuxmacoswindowsPython
Recongo-dorkThe fastest dork scanner written in Go.linuxmacoswindowsGo
ReconhakrevdnsSmall, fast tool for performing reverse DNS lookups en masse.linuxmacoswindowsGo
ReconCT_subdomainsAn hourly updated list of subdomains gathered from certificate transparency logssubdomainslinuxmacoswindows
ReconzdnsFast CLI DNS Lookup TooldnslinuxmacoswindowsGo
ReconSTEWSA Security Tool for Enumerating WebSocketslinuxmacoswindowsPython
ReconlazyreconThis script is intended to automate your reconnaissance process in an organized fashionlinuxmacoswindowsShell
ReconHostHunterRecon tool for discovering hostnames using OSINT techniques.osintlinuxmacoswindowsPython
ReconLepusSubdomain findersubdomainslinuxmacoswindowsPython
RecondnsprobeDNSProb (beta) is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.dnslinuxmacoswindowsGo
ReconreconftwreconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilitieslinuxmacoswindowsShell
RecongobusterDirectory/File, DNS and VHost busting tool written in GosubdomainslinuxmacoswindowsGo
ReconAmassIn-depth Attack Surface Mapping and Asset DiscoverysubdomainslinuxmacoswindowsGo
RecongauFetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.urllinuxmacoswindowsGo
ReconxnLinkFinderA python tool used to discover endpoints (and potential parameters) for a given targetjs-analysislinuxmacoswindowsPython
RecongetJSA tool to fastly get all javascript sources/filesjs-analysislinuxmacoswindowsGo
Recondnsxdnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.dnslinuxmacoswindowsGo
ReconfhcFast HTTP Checker.linuxmacoswindowsRust
ReconHydraReconAll In One, Fast, Easy Recon ToollinuxmacoswindowsPython
RecongitrobReconnaissance tool for GitHub organizationslinuxmacoswindowsGo
ReconsubfinderSubfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing.subdomainslinuxmacoswindowsGo
ReconJSFScan.shAutomation for javascript recon in bug bounty.js-analysislinuxmacoswindowsShell
Reconx8Hidden parameters discovery suitelinuxmacoswindowsRust
Recongithub-subdomainsFind subdomains on GitHubsubdomainslinuxmacoswindowsGo
ReconsubzySubdomain takeover vulnerability checkersubdomains takeoverlinuxmacoswindowsGo
FuzzerkiterunnerContextual Content Discovery ToollinuxmacoswindowsGo
FuzzerdotdotpwnDotDotPwn - The Directory Traversal Fuzzerpath-traversallinuxmacoswindowsPerl
FuzzerBruteXAutomatically brute force all services running on a target.linuxmacoswindowsShell
FuzzerSSRFmapAutomatic SSRF fuzzer and exploitation toolssrflinuxmacoswindowsPython
FuzzerClairvoyanceObtain GraphQL API schema even if the introspection is disabledgraphqllinuxmacoswindowsPython
FuzzerhashcatWorld's fastest and most advanced password recovery utilitylinuxmacoswindowsC
FuzzerSmuggleFuzzA rapid HTTP downgrade smuggling scanner written in Go.smuggle fuzzlinuxmacoswindowsGo
FuzzerCrackQLCrackQL is a GraphQL password brute-force and fuzzing utility.graphqllinuxmacoswindowsPython
FuzzerSSTImapAutomatic SSTI detection tool with interactive interfacesstilinuxmacoswindowsPython
Fuzzerc-jwt-crackerJWT brute force cracker written in CjwtlinuxmacoswindowsC
Fuzzerjwt-hack🔩 jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce)jwtlinuxmacoswindowsGo
FuzzermedusaFastest recursive HTTP fuzzer, like a Ferrari.linuxmacoswindowsGo
FuzzerwfuzzWeb application fuzzerlinuxmacoswindowsPython
FuzzerParamPamPamThis tool for brute discover GET and POST parameters.param cache-vulnlinuxmacoswindowsPython
FuzzerfuzzparamA fast go based param miner to fuzz possible parameters a URL can have.paramlinuxmacoswindowsGo
FuzzercrlfuzzA fast tool to scan CRLF vulnerability written in GocrlflinuxmacoswindowsShell
FuzzerSSRFireAn automated SSRF finder. Just give the domain name and your server and chillssrflinuxmacosShell
FuzzerBatchQLGraphQL security auditing script with a focus on performing batch GraphQL queries and mutationsgraphqllinuxmacoswindowsPython
FuzzerGraphQLmapGraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.graphqllinuxmacoswindowsPython
FuzzerferoxbusterA fast, simple, recursive content discovery tool written in Rust.linuxmacoswindowsRust
FuzzerppfuzzA fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀prototypepollution prototype-pollutionlinuxmacoswindowsRust
Fuzzerjwt-crackerSimple HS256 JWT token brute force crackerjwtlinuxmacoswindowsJavaScript
FuzzerffufFast web fuzzer written in GolinuxmacoswindowsGo
FuzzerheaderpwnA fuzzer for finding anomalies and analyzing how servers respond to different HTTP headersheaderlinuxmacoswindowsGo
Fuzzerthc-hydrahydralinuxmacoswindowsC
ScannerDeepVioletTool for introspection of SSL\TLS sessionsssllinuxmacoswindowsJava
ScannerTaipanWeb application vulnerability scannerlinuxmacoswindows
ScannerPPScanClient Side Prototype Pollution Scannerprototypepollution prototype-pollutionlinuxmacoswindowsJavaScript
ScannerOralyzerOpen Redirection AnalyzerlinuxmacoswindowsPython
ScannerPwnXSSVulnerability (XSS) scanner exploitxsslinuxmacoswindowsPython
ScannerNoSQLMapAutomated NoSQL database enumeration and web application exploitation tool.nosqlilinuxmacoswindowsPython
Scannerdontgo403Tool to bypass 40X response codes.403linuxmacoswindowsGo
ScannernosqliNoSql Injection CLI toolnosqlilinuxmacoswindowsGo
ScannerConfusedDotnetTool to check for dependency confusion vulnerabilities in NuGet package management systemsdependency-confusionwindowsC#
Scannercorsair_scanCorsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).corslinuxmacoswindowsPython
ScannerarachniWeb Application Security Scanner FrameworklinuxmacoswindowsRuby
ScannerAWSBucketDumpSecurity Tool to Look For Interesting Files in S3 Bucketss3linuxmacoswindowsPython
ScannergitleaksScan git repos (or files) for secrets using regex and entropy 🔑linuxmacoswindowsGo
ScannerautopoisonerWeb cache poisoning vulnerability scanner.cache-vulnlinuxmacoswindowsPython
ScannerheadiCustomisable and automated HTTP header injectionheaderlinuxmacoswindowsGo
ScannernmapNmap - the Network Mapper. Github mirror of official SVN repository.portscanlinuxmacoswindowsC
ScannerDSSSDamn Small SQLi ScannersqlilinuxmacoswindowsPython
ScannerdeadlinksHealth checks for your documentation links.broken-linklinuxmacoswindowsPython
Scannerssrf-sheriffA simple SSRF-testing sheriff written in GossrflinuxmacoswindowsGo
ScannerhinjectHost Header Injection CheckerheaderlinuxmacoswindowsGo
ScannerChromium-based-XSS-Taint-TrackingCyclops is a web browser with XSS detection feature, it is chromium-based xss detection that used to find the flows from a source to a sink.xsslinuxmacoswindows
ScannernucleiNuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use.linuxmacoswindowsGo
ScannerDeadsniperA fast, specialized dead-link checkerbroken-linklinuxmacoswindowsGo
ScannerplutionPrototype pollution scanner using headless chromeprototypepollution prototype-pollutionlinuxmacoswindowsGo
Scannerh2csmugglerHTTP Request Smuggling Detection ToolsmugglelinuxmacoswindowsGo
Scannerhttp-request-smugglingHTTP Request Smuggling Detection ToollinuxmacoswindowsPython
Scannerscan4allOfficial repository vuls ScanlinuxmacoswindowsGo
Scannerwebsocket-connection-smugglerwebsocket-connection-smugglersmugglelinuxmacoswindowsGo
Scannerdependency-confusion-scannerThis small repo is meant to scan Github's repositories for potential Dependency confusion vulnerabilities.dependency-confusionlinuxmacoswindowsPython
Scannerzap-cliA simple tool for interacting with OWASP ZAP from the commandline.linuxmacoswindowszapPython
ScannerV3n0M-ScannerPopular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulnssqli xss lfi rfilinuxmacoswindowsPython
ScannerXSpearPowerfull XSS Scanning and Parameter analysis tool&gemxsslinuxmacoswindowsRuby
ScannerS3cret ScannerHunting For Secrets Uploaded To Public S3 Bucketss3linuxmacoswindowsPython
ScannergitGrabergitGraberlinuxmacoswindowsPython
ScannerrapidscanThe Multi-Tool Web Vulnerability Scanner.linuxmacoswindowsPython
ScannersqlmapAutomatic SQL injection and database takeover toolsqlilinuxmacoswindowsPython
ScannerFockCacheMinimalized Test Cache Poisoningcache-vulnlinuxmacoswindowsGo
ScannerDeadFinderFind dead-links (broken links)broken-linklinuxmacoswindowsRuby
ScannerNoXssFaster xss scanner,support reflected-xss and dom-xssxsslinuxmacoswindowsPython
Scannerxsinator.comXS-Leak Browser Test SuitelinuxmacoswindowsJavaScript
ScannerVHostScanA virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.linuxmacoswindowsPython
Scannerweb_cache_poisonweb cache poison - Top 1 web hacking technique of 2019cache-vulnlinuxmacoswindowsShell
ScannerxsserCross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.xsslinuxmacoswindowsPython
ScannerLFISuiteTotally Automatic LFI Exploiter (+ Reverse Shell) and ScannerlinuxmacoswindowsPython
Scannerhttp2smuglThis tool helps to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -> HTTP/1.1 conversion by the frontend server.linuxmacoswindowsGo
ScannerwpscanWPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites.linuxmacoswindowsRuby
ScannerdepenfusionA powerful pentesting tool for detecting and exploiting dependency confusion vulnerabilities in Node.js projectsdependency-confusionlinuxmacoswindowsPython
ScannersmugglerSmuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3smugglelinuxmacoswindowsPython
Scannerjsprimea javascript static security analysis tooljs-analysislinuxmacoswindowsJavaScript
ScannerconfusedTool to check for dependency confusion vulnerabilities in multiple package management systemsdependency-confusionlinuxmacoswindowsGo
Scannergithub-searchTools to perform basic search on GitHub.linuxmacoswindowsJavaScript
Scannerfindom-xssA fast DOM based XSS vulnerability scanner with simplicity.xsslinuxmacoswindowsShell
ScannerXssPyWeb Application XSS ScannerxsslinuxmacoswindowsPython
ScannerWeb-Cache-Vulnerability-ScannerWeb Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).cache-vulnlinuxmacoswindowsGo
ScannercommixAutomated All-in-One OS Command Injection Exploitation Tool.exploitlinuxmacoswindowsPython
Scannerdalfox🌘🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.xsslinuxmacoswindowsGo
ScannerppmapA scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.prototypepollution prototype-pollutionlinuxmacoswindowsGo
ScannerDirDarDirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it403linuxmacoswindowsGo
ScannerxsssniperAn automatic XSS discovery toolxsslinuxmacoswindowsPython
ScannerS3ScannerScan for open AWS S3 buckets and dump the contentss3linuxmacoswindowsPython
ScannerStrikerStriker is an offensive information and vulnerability scanner.linuxmacoswindowsPython
ScannerCorsMeCross Origin Resource Sharing MisConfiguration ScannercorslinuxmacoswindowsGo
ScannerwpreconHello! Welcome. Wprecon (Wordpress Recon), is a vulnerability recognition tool in CMS Wordpress, 100% developed in Go.linuxmacoswindowsGo
ScannerniktoNikto web server scannerlinuxmacoswindowsPerl
ScannerSQLiDetectorSimple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.sqlilinuxmacoswindowsPython
ScannerxsscrapyXSS/SQLi spider. Give it a URL and it'll test every link it finds for XSS and some SQLi.xsslinuxmacoswindowsPython
ScannerpphackThe Most Advanced Client-Side Prototype Pollution Scannerprototypepollution prototype-pollutionlinuxmacoswindowsGo
Scannera2svAuto Scanning to SSL VulnerabilityssllinuxmacoswindowsPython
ScannerOpenRedireXA Fuzzer for OpenRedirect issueslinuxmacoswindowsPython
ScannerCorsyCORS Misconfiguration ScannercorslinuxmacoswindowsPython
ScannerHRSHTTP Request Smuggling demonstration Perl script, for variants 1, 2 and 5 in my BlackHat US 2020 paper HTTP Request Smuggling in 2020.linuxmacoswindowsPerl
ScannerdomdigDOM XSS scanner for Single Page ApplicationsxsslinuxmacoswindowsJavaScript
ScannerhttprobeTake a list of domains and probe for working HTTP and HTTPS serverslinuxmacoswindowsGo
Scannerws-smugglerWebSocket Connection SmugglersmugglelinuxmacoswindowsGo
ScannerDOMPurifyDOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:xsslinuxmacoswindowsJavaScript
Scannersqlivmassive SQL injection vulnerability scannersqlilinuxmacoswindowsPython
ScannerXSStrikeMost advanced XSS scanner.xsslinuxmacoswindowsPython
Scannertestssl.shTesting TLS/SSL encryption anywhere on any portssllinuxmacoswindowsShell
ScannerdittoA tool for IDN homograph attacks and detection.linuxmacoswindowsGo
ScannertplmapServer-Side Template Injection and Code Injection Detection and Exploitation ToollinuxmacoswindowsPython
ExploitghauriAn advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flawssqlilinuxmacoswindowsPython
ExploitLiffyLocal file inclusion exploitation toollfilinuxmacoswindowsPython
ExploitxxeservA mini webserver with FTP support for XXE payloadslinuxmacoswindowsGo
ExploitXXEinjectorTool for automatic exploitation of XXE vulnerability using direct and different out of band methods.xxelinuxmacoswindowsRuby
ExploitbeefThe Browser Exploitation Framework ProjectxsslinuxmacoswindowsRuby
ExploitroprA blazing fast™ multithreaded ROP Gadget finder. ropperroplinuxmacoswindowsRust
ExploitXSRFProbeThe Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.linuxmacoswindowsPython
ExploitSn1perAutomated pentest framework for offensive security expertslinuxmacoswindowsShell
ExploitGopherusThis tool generates gopher link for exploiting SSRF and gaining RCE in various serversssrflinuxmacoswindowsPython
ExploitBaRMIeJava RMI enumeration and attack tool.RMIlinuxmacoswindowsJava
ExploitXXExploiterTool to help exploit XXE vulnerabilitiesxxelinuxmacoswindowsTypeScript
Exploitof-CORSIdentifying and exploiting CORS misconfigurations on the internal networkscorslinuxmacoswindowsPython
ExploitsingularityA DNS rebinding attack framework.linuxmacoswindowsJavaScript
ExploitSQLNinjaSqlninja is a tool targeted to exploit SQL Injection vulnerabilities.sqlilinuxmacosPerl
ExploittoxssinAn XSS exploitation command-line interface and payload generator.xsslinuxmacoswindowsPython
UtilsjsfuckWrite any JavaScript with 6 CharactersxsslinuxmacoswindowsJavaScript
UtilsBlacklist3rproject-blacklist3rlinuxmacoswindowsC#
UtilsREcollapseREcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applicationsfuzzlinuxmacoswindowsPython
UtilsurlgrabA golang utility to spider through a website searching for additional links.urllinuxmacoswindowsGo
UtilshoppscotchOpen source API development ecosystemhttplinuxmacoswindowsTypeScript
UtilsburlA Broken-URL CheckerurllinuxmacoswindowsGo
UtilsbountyplzAutomated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)reportlinuxmacoswindowsShell
Utilsnuclei-wordfence-cveEvery single day new templates are added to this repo based on updates on Wordfence.comnuclei-templateslinuxmacoswindowsPython
Utilssecurity-crawl-mazeSecurity Crawl Maze is a comprehensive testbed for web security crawlers. It contains pages representing many ways in which one can link resources from a valid HTML document.crawllinuxmacoswindowsHTML
UtilsgotestwafAn open-source project in Golang to test different web application firewalls (WAF) for detection logic and bypasseslinuxmacoswindowsGo
UtilshurlHurl, run and test HTTP requests.linuxmacoswindowsRust
Utilssecurity-research-pocsProof-of-concept codes created as part of security research done by Google Security Team.linuxmacoswindowsC++
UtilshttptoolkitHTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Maclinuxmacoswindows
UtilscentCommunity edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place.nuclei-templateslinuxmacoswindowsGo
Utilspentest-toolsCustom pentesting toolslinuxmacoswindowsPython
UtilsurlprobeUrls status code & content length checkerurllinuxmacoswindowsGo
Utilszip-bombCreate a ZIPBomb for a given uncompressed size (flat and nested modes).zipbomblinuxmacoswindowsPython
UtilswuzzInteractive cli tool for HTTP inspectionhttplinuxmacoswindowsGo
UtilsCyberChefThe Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysislinuxmacoswindowsJavaScript
Utilsgrcgeneric colouriserlinuxmacoswindowsPython
UtilsGQLSpectionparses GraphQL introspection schema and generates possible queriesgraphqllinuxmacoswindowsPython
UtilsmubengAn incredibly fast proxy checker & IP rotator with ease.linuxmacoswindowsGo
UtilsqsreplaceAccept URLs on stdin, replace all query string values with a user-supplied valuelinuxmacoswindowsGo
Utilsbruteforce-listsSome files for bruteforcing certain things.wordlist documentslinuxmacoswindowsTxt
Utilsxssor2XSS'OR - Hack with JavaScript.xsslinuxmacoswindowsJavaScript
UtilsinteractshAn OOB interaction gathering server and client libraryoastlinuxmacoswindowsGo
UtilsautochromeThis tool downloads, installs, and configures a shiny new copy of Chromium.linuxmacoswindowsHTML
Utilscf-checkCloudflare Checker written in GolinuxmacoswindowsGo
UtilsAssetnote WordlistsAutomated & Manual Wordlists provided by Assetnotewordlist documentslinuxmacoswindowsCSS
UtilshacksA collection of hacks and one-off scriptslinuxmacoswindowsGo
UtilsZipBombA simple implementation of ZipBomb in PythonzipbomblinuxmacoswindowsPython
UtilsgodeclutterDeclutters URLs in a fast and flexible way, for improving input for web hacking automations such as crawlers and vulnerability scans.urllinuxmacoswindowsGo
UtilsfzfA command-line fuzzy finderlinuxmacoswindowsGo
UtilsgxssBlind XSS service alerting over slack or emailxss blind-xsslinuxmacoswindowsGo
UtilsdocemUility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids)xxe xsslinuxmacoswindowsPython
UtilsAtlasQuick SQLMap Tamper SuggestersqlilinuxmacoswindowsPython
UtilsPhoenixhahwul's online toolsonlinelinuxmacoswindowsJavaScript
UtilshakcheckurlTakes a list of URLs and returns their HTTP response codeslinuxmacoswindowsGo
UtilstiscriptsTurbo Intruder ScriptslinuxmacoswindowsPython
UtilsgitlsListing git repository from URL/User/OrglinuxmacoswindowsGo
Utilsysoserial.netDeserialization payload generator for a variety of .NET formattersdeserializelinuxmacoswindowsC#
UtilsdnsobserverA handy DNS service written in Go to aid in the detection of several types of blind vulnerabilities. It monitors a pentester's server for out-of-band DNS interactions and sends lookup notifications via Slack.oast dnslinuxmacoswindowsGo
UtilsquickjackQuickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.linuxmacoswindowsJavaScript
UtilsblistenerBlind-XSS listener with payloadsxss blind-xsslinuxmacoswindowsGo
Utilstemplate-generatorA simple variable based template editor using handlebarjs+strapdownjs. The idea is to use variables in markdown based files to easily replace the variables with content. Data is saved temporarily in local storage. PHP is only needed to generate the list of files in the dropdown of templates.linuxmacoswindowsJavaScript
Utilspwncatpwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)linuxmacoswindowsShell
Utilss3reverseThe format of various s3 buckets is convert in one format. for bugbounty and security testing.s3linuxmacoswindowsGo
UtilsPoC-in-GitHub📡 PoC auto collect from GitHub. Be careful malware.linuxmacoswindows
Utilsoxml_xxeA tool for embedding XXE/XML exploits into different filetypeslinuxmacoswindowsRuby
Utilsgraphql-voyager🛰️ Represent any GraphQL API as an interactive graphgraphqllinuxmacoswindowsTypeScript
Utilsdifftastica structural diff that understands syntaxdifflinuxmacoswindowsRust
UtilswssipApplication for capturing, modifying and sending custom WebSocket data from client to server and vice versa.linuxmacoswindowsJavaScript
UtilsgronMake JSON greppable!jsonlinuxmacoswindowsGo
UtilsGadgetProbeProbe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.deserializelinuxmacoswindowsJava
UtilseoycEncoding Only Your ChoicesencodelinuxmacoswindowsCrystal
UtilsanewA tool for adding new lines to files, skipping duplicateslinuxmacoswindowsGo
UtilsbatA cat(1) clone with wings.linuxmacoswindowsRust
UtilsslackcatCLI utility to post files and command output to slacknotifylinuxmacoswindowsGo
UtilsRedcloudAutomated Red Team Infrastructure deployement using DockerinfralinuxmacoswindowsPython
UtilsezXSSezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.xss blind-xsslinuxmacoswindowsPHP
UtilsxlessThe Serverless Blind XSS Appxss blind-xsslinuxmacoswindowsJavaScript
UtilsgfA wrapper around grep, to help you grep for thingslinuxmacoswindowsGo
UtilsgrexA command-line tool and library for generating regular expressions from user-provided test caseslinuxmacoswindowsRust
UtilspetSimple command-line snippet manager, written in Go.linuxmacoswindowsGo
UtilscurlA command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, MQTT, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful featureslinuxmacoswindowsC
UtilsdsieveFilter and enrich a list of subdomains by levelsubdomainslinuxmacoswindowsGo
UtilsCSP EvaluatorOnline CSP Evaluator from googlecsplinuxmacoswindows
UtilsFindsploitFind exploits in local and online databases instantlyexploitlinuxmacoswindowsShell
Utilsweaponised-XSS-payloadsXSS payloads designed to turn alert(1) into P1xss documentslinuxmacoswindowsJavaScript
UtilsSequenceDiagramOnline tool for creating UML sequence diagramsonlinelinuxmacoswindows
UtilsPayloadsAllTheThingsA list of useful payloads and bypass for Web Application Security and Pentest/CTFlinuxmacoswindowsPython
UtilsXSS-CatcherFind blind XSS but why not gather data while you're at it.xss blind-xsslinuxmacoswindowsPython
UtilsSerializationDumperA tool to dump Java serialization streams in a more human readable form.deserializelinuxmacoswindowsJava
UtilsysoserialA proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.deserializelinuxmacoswindowsJava
Utilsgithub-regexpBasically a regexp over a GitHub search.linuxmacoswindowsGo
Utilsreverse-shell-generatorHosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)payloadlinuxmacoswindowsJavaScript
UtilsIntruderPayloadslinuxmacoswindowsburpBlitzBasic
Utilsgee🏵 Gee is tool of stdin to each files and stdout. It is similar to the tee command, but there are more functions for convenience. In addition, it was written as golinuxmacoswindowsGo
UtilsSecListsSecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place.wordlist documentslinuxmacoswindowsTxt
UtilsTukTukTool for catching and logging different types of requests.oastlinuxmacoswindowsGo
UtilsEmissarySend notifications on different channels such as Slack, Telegram, Discord etc.notifylinuxmacoswindowsGo
Utilscan-i-take-over-xyz"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.linuxmacoswindows
UtilsgotatorGotator is a tool to generate DNS wordlists through permutations.linuxmacoswindowsGo
UtilsfffThe Fairly Fast Fetcher. Requests a bunch of URLs provided on stdin fairly quickly.urllinuxmacoswindowsGo
UtilshbxssSecurity test tool for Blind XSSxss blind-xsslinuxmacoswindowsRuby
UtilsboastThe BOAST Outpost for AppSec Testing (v0.1.0)oastlinuxmacoswindowsGo
UtilsunfurlPull out bits of URLs provided on stdinurllinuxmacoswindowsGo
Utils230-OOBAn Out-of-Band XXE server for retrieving file contents over FTP.xxelinuxmacoswindowsPython
UtilsGf-PatternsGF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic) parameters greplinuxmacoswindows
Utilsmissing-cve-nuclei-templatesWeekly updated list of missing CVEs in nuclei templates official repositorynuclei-templateslinuxmacoswindowsTxt
Utilsob_hacky_slackHacky Slack - a bash script that sends beautiful messages to SlacknotifylinuxmacoswindowsShell
Utilsnuclei-templatesCommunity curated list of templates for the nuclei engine to find security vulnerabilities.nuclei-templateslinuxmacoswindowsGo
Utilshttpiemodern, user-friendly command-line HTTP client for the API erahttplinuxmacoswindowsPython
Utilsxss-cheatsheet-dataThis repository contains all the XSS cheatsheet data to allow contributions from the community.xsslinuxmacoswindows
UtilsBug-Bounty-ToolzBBT - Bug Bounty ToolslinuxmacoswindowsPython
UtilsClipboardAn external brain that remembers anything, anytime, anywhere.clipboardlinuxmacoswindowsC++
EnvGlueApplication Security AutomationlinuxmacoswindowsRuby
EnvCrimsonWeb Application Security Testing automation.linuxmacoswindowsPython
Envpentest-envPentest environment deployer (kali linux + targets) using vagrant and chef.pentestlinuxmacoswindowsRuby

Bookmarklets

TypeNameDescriptionStarTagsBadges

Browser Addons

TypeNameDescriptionStarTagsBadges
ReconDotGitAn extension for checking if .git is exposed in visited websiteslinuxmacoswindowsfirefoxchromeJavaScript
ReconWayback MachineHistory of websitelinuxmacoswindowssafari
Utilsjsonwebtoken.github.ioJWT En/Decode and VerifyjwtlinuxmacoswindowsJavaScript
Utilscookie-quick-managerAn addon to manage (view, search, create, edit, remove, backup, restore) cookies on Firefox.cookielinuxmacoswindowsfirefoxJavaScript
UtilsUser-Agent Switcherquick and easy way to switch between user-agents.linuxmacoswindowsfirefox
UtilsFirefox Multi-Account ContainersFirefox Multi-Account Containers lets you keep parts of your online life separated into color-coded tabslinuxmacoswindowsfirefoxJavaScript
UtilsEdit-This-CookieEditThisCookie is the famous Google Chrome/Chromium extension for editing cookiescookielinuxmacoswindowschromeJavaScript
UtilsZAP Browser ExtensionA browser extension which allows ZAP to interact directly with the browser.browser-recordlinuxmacoswindowsfirefoxchromezapTypeScript
Utilsfirefox-container-proxyAssign a proxy to a Firefox containerlinuxmacoswindowsfirefoxJavaScript
UtilsHack-ToolsThe all-in-one Red Team extension for Web Pentester 🛠linuxmacoswindowsfirefoxchromesafariTypeScript
UtilsDark ReaderDark mode to any sitedarkmodelinuxmacoswindowsfirefoxchromeTypeScript
UtilspostMessage-trackerA Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-iconjs-analysislinuxmacoswindowschromeJavaScript
Utilsclear-cacheAdd-on to clear browser cache with a single click or via the F9 key.linuxmacoswindowsfirefoxchromeJavaScript
Utilseval_villainA Firefox Web Extension to improve the discovery of DOM XSS.xsslinuxmacoswindowsfirefoxzapJavaScript
UtilsPwnFoxFirefox/Burp extension that provide usefull tools for your security audit.linuxmacoswindowsfirefoxburpJavaScript
UtilsDark Reader for SafariDark mode to any sitelinuxmacoswindowssafari
UtilsDOMLogger++A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.dom xsslinuxmacoswindowsfirefoxchromeJavaScript
UtilsMM3 ProxySwitchProxy Switch in Firefox and ChromelinuxmacoswindowsfirefoxchromeJavaScript

Burpsuite, Caido and ZAP Addons

TypeNameDescriptionStarTagsBadges
ReconHUNTIdentifies common parameters vulnerable to certain vulnerability classesparamlinuxmacoswindowszapburpKotlin
ReconDr. WatsonDr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful informationparam subdomainslinuxmacoswindowsburpPython
ReconBurpJSLinkFinderjs-analysislinuxmacoswindowsburpPython
Reconreflected-parametersparamlinuxmacoswindowsburpJava
Reconattack-surface-detector-burpThe Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parametersendpoint url attack-surfacelinuxmacoswindowsburpJava
ReconBurpSuite-Secret_Finderlinuxmacoswindowsburp
Reconattack-surface-detector-zapThe Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parametersendpoint url attack-surfacelinuxmacoswindowszapJava
Reconburp-retire-jsjs-analysislinuxmacoswindowsburpJavaScript
FuzzerGAPThis is an evolution of the original getAllParams extension for Burp. Not only does it find more potential parameters for you to investigate, but it also finds potential links to try these parameters on.paramlinuxmacoswindowsburpPython
Fuzzerparam-minerParam Minerparam cache-vulnlinuxmacoswindowsburpJava
ScannerAuthMatrixaaalinuxmacoswindowsburpPython
ScannerAutorizeaaalinuxmacoswindowsburpPython
Scannercsp-auditorcsplinuxmacoswindowszapburpJava
Scannerhttp-request-smugglersmugglelinuxmacoswindowsburpJava
Scannercollaborator-everywhereoastlinuxmacoswindowsburpJava
ScannerBurpSuiteHTTPSmugglersmugglelinuxmacoswindowsburpJava
UtilsMap LocalZAP add-on which allows mapping of responses to content of a chosen local file.linuxmacoswindowszapJava
UtilsreflectlinuxmacoswindowszapKotlin
Utilscaidopecaidope - caido pluginlinuxmacoswindowscaidoTypeScript
UtilsWeb3 DecoderBurp Extension for Web3web3linuxmacoswindowsburpJava
UtilsnotebookNotebook Caido PluginnotelinuxmacoswindowscaidoTypeScript
UtilsCaidoReflectorAutomatically look for paramater reflections in the HTTP responsexsslinuxmacoswindowscaidoTypeScript
UtilsBurpCustomizerBecause just a dark theme wasn't enough!linuxmacoswindowsburpJava
UtilsAuthMatrixAutomated HTTP Request Repeating With Burp SuitelinuxmacoswindowsburpJava
UtilsinqllinuxmacoswindowsburpPython
Utilsburp-send-tolinuxmacoswindowsburpJava
UtilsHTTPSignaturesA Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.linuxmacoswindowsburpJava
UtilsgRPC-Web Pentest SuitegRPC-Pentest-Suite is set of tools for pentesting / hacking gRPC Web (gRPC-Web) applications.gRPC-WebburplinuxmacoswindowsPython
UtilsEvenBetterExtensionsEvenBetterExtensions allows you to quicky install and keep updated Caido extensions.encode ssrf darkmodelinuxmacoswindowscaidoTypeScript
UtilsfemidalinuxmacoswindowsburpPython
UtilstaboratoroastlinuxmacoswindowsburpJava
UtilsDecoder-ImprovedImproved decoder for Burp SuitelinuxmacoswindowsburpJava
Utilspcap-burpPcap importer for BurplinuxmacoswindowsburpJava
UtilsknifeA burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅linuxmacoswindowsJava
Utilsburp-piperlinuxmacoswindowsburpKotlin
UtilsblackboxprotobufBlackbox protobuf is a Burp Suite extension for decoding and modifying arbitrary protobuf messages without the protobuf type definition.linuxmacoswindowsburpPython
UtilsStepperlinuxmacoswindowsburpJava
utilsNeonmarkerlinuxmacoswindowszapJava
UtilsargumentinjectionhammerA Burp Extension designed to identify argument injection vulnerabilities.linuxmacoswindowsburpPython
Utilszap-hudlinuxmacoswindowszapJava
UtilsBurpSuiteLoggerPlusPluslinuxmacoswindowsburpJava
Utilsburp-exporterlinuxmacoswindowsburpPython
UtilsBurpBountylinuxmacoswindowsburpBlitzBasic
UtilsAWSSignerBurp Extension for AWS SigninglinuxmacoswindowsburpJava
Utilsturbo-intruderlinuxmacoswindowsburpKotlin
UtilssafecopylinuxmacoswindowsburpJava
UtilsEvenBetterEvenBetter is a frontend Caido plugin that makes the Caido experience even betterencode ssrf darkmodelinuxmacoswindowscaidoTypeScript
Utilshttp-script-generatorlinuxmacoswindowszapburpJava
utilsowasp-zap-jwt-addonjwtlinuxmacoswindowszapJava
UtilsBerserkoBurp Suite extension to perform Kerberos authenticationlinuxmacoswindowsburpJava
Utilscommunity-scriptslinuxmacoswindowszapJavaScript

Thanks to (Contributor)

WHW's open-source project and made it with ❤️ if you want contribute this project, please see CONTRIBUTING.md and Pull-Request with cool your contents.