FWDSEC / burp-auto-gqlLinks
A plugin for Burp Suite Pro that uses the GraphQL schema to begin Active Scanning the entire endpoint.
☆40Updated last month
Alternatives and similar repositories for burp-auto-gql
Users that are interested in burp-auto-gql are comparing it to the libraries listed below
Sorting:
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆102Updated last year
- BChecks collection for Burp Suite Professional☆101Updated last year
- Extract JavaScript files from burp suite project with ease.☆97Updated 3 years ago
- ☆32Updated last year
- For unpacking base64:ed "Save items"-content from Burp (From search + proxy history)☆54Updated 9 months ago
- Golang tool which helps dropping the irrelevant entries from your ffuf result file.☆140Updated last year
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆80Updated 2 years ago
- Results from analyzing data gathered from 1.6 billion subdomains☆32Updated last year
- A tool for monitoring bug bounty programs across multiple platforms to track scope changes.☆31Updated last week
- ☆90Updated 4 years ago
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆157Updated last year
- ☆96Updated 4 years ago
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆151Updated last year
- Identify virtual hosts by similarity comparison☆133Updated last year
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆82Updated last week
- Mine URLs from Browser's Heap Snapshot for fun and profit☆64Updated 2 years ago
- Some of the gf patterns which i use☆45Updated 3 years ago
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 3 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆120Updated 2 years ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆82Updated last year
- JSSCM detects expired domains for Stored XSS exploitation during browsing.☆54Updated 8 months ago
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆79Updated 2 years ago
- ☆64Updated 2 years ago
- An MS Sharepoint and Frontpage Auditing Tool☆57Updated last year
- Prototype Pollution Scanner☆129Updated 4 years ago
- Check AWS S3 instances for read/write/delete access☆122Updated 3 years ago
- A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing☆140Updated 2 years ago
- ☆85Updated 3 years ago
- A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs☆74Updated 5 months ago
- Finds graphql queries in javascript files☆65Updated last year