BishopFox / sj
A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.
☆644Updated 3 weeks ago
Alternatives and similar repositories for sj:
Users that are interested in sj are comparing it to the libraries listed below
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆634Updated last year
- ☆484Updated last year
- The Distributed Scanning Framework for Everybody! Control Your Infrastructure, Scale Your Scanning—On Your Terms. Easily distribute arbit…☆483Updated last week
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.☆65Updated last year
- AI-powered ffuf wrapper☆478Updated 5 months ago
- CT Log Scanner☆351Updated last month
- i will upload more templates here to share with the comunity.☆543Updated last year
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆970Updated this week
- ☆524Updated 10 months ago
- Discover new target domains using Content Security Policy☆426Updated 2 weeks ago
- hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.☆444Updated 3 years ago
- TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines fo…☆351Updated 5 months ago
- A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows☆290Updated last year
- Fast and customizable vulnerability scanner For JIRA written in Python☆319Updated 4 months ago
- An IIS short filename enumeration tool☆925Updated 5 months ago
- Bambdas collection for Burp Suite Professional and Community.☆306Updated last week
- ☆386Updated this week
- User-Agent , X-Forwarded-For and Referer SQLI Fuzzer☆382Updated last year
- AllForOne allows bug bounty hunters and security researchers to collect all Nuclei YAML templates from various public repositories,☆643Updated last year
- Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration test…☆374Updated this week
- Gotator is a tool to generate DNS wordlists through permutations.☆477Updated 2 years ago
- ☆443Updated 3 months ago
- All About Dependency Confusion Attack, (Detecting, Finding, Mitigating)☆287Updated last year
- jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice☆272Updated last year
- Fast and customizable subdomain wordlist generator using DSL☆805Updated 3 weeks ago
- A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidde…☆366Updated last month
- A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery☆304Updated 5 months ago
- Simple tool to scan a website for (DOM-based) XSS vulnerabilities and Open Redirects.☆237Updated 2 months ago
- A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.☆575Updated 2 months ago
- BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for c…☆409Updated 3 months ago