FWDSEC / burp-auto-gqlLinks
A plugin for Burp Suite Pro that uses the GraphQL schema to begin Active Scanning the entire endpoint.
☆38Updated last year
Alternatives and similar repositories for burp-auto-gql
Users that are interested in burp-auto-gql are comparing it to the libraries listed below
Sorting:
- ☆32Updated last year
- Extract JavaScript files from burp suite project with ease.☆90Updated 3 years ago
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- A tool for monitoring bug bounty programs across multiple platforms to track scope changes.☆25Updated last month
- ☆63Updated 2 years ago
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆67Updated last year
- BChecks collection for Burp Suite Professional☆98Updated last year
- Burp extension to check and exploit the IIS Tilde Enumeration/IIS 8.3 Short Filename Disclosure vulnerability☆59Updated 2 years ago
- For unpacking base64:ed "Save items"-content from Burp (From search + proxy history)☆50Updated 3 months ago
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆98Updated last year
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆77Updated last year
- ☆95Updated 3 years ago
- Golang tool which helps dropping the irrelevant entries from your ffuf result file.☆137Updated 9 months ago
- vīlicus is a bug bounty api dashboard☆41Updated last year
- IIS shortname scanner + bruteforce☆52Updated last year
- ☆89Updated 3 years ago
- Improve automated and semi-automated active scanning in Burp Pro☆61Updated 3 weeks ago
- Results from analyzing data gathered from 1.6 billion subdomains☆27Updated 8 months ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆119Updated 2 years ago
- Modified Nuclei Templates Version to FUZZ Host Header☆49Updated 3 years ago
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆44Updated last year
- Identify virtual hosts by similarity comparison☆126Updated 10 months ago
- Detects request smuggling via HTTP/2 downgrades.☆92Updated 2 years ago
- Mine URLs from Browser's Heap Snapshot for fun and profit☆63Updated last year
- An MS Sharepoint and Frontpage Auditing Tool☆49Updated 7 months ago
- Trickest Workflow for discovering log4j vulnerabilities and gathering the newest community payloads.☆111Updated 3 years ago
- 🚀 Sling Shot R3con: Automate Your Bug Bounty and Pentest Reconnaissance with Project Discovery tools 🎯☆25Updated last year
- ☆57Updated 5 months ago
- JSSCM detects expired domains for Stored XSS exploitation during browsing.☆50Updated 2 months ago
- Some of the gf patterns which i use☆43Updated 3 years ago