FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).
☆183Jul 8, 2024Updated last year
Alternatives and similar repositories for FlowAnalyzer
Users that are interested in FlowAnalyzer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Create tar/zip archives that try to exploit zipslip vulnerability.☆48Sep 20, 2024Updated last year
- When good OAuth apps go rogue. Documents observed OAuth application tradecraft☆86Apr 7, 2026Updated last month
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆38Sep 25, 2024Updated last year
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆30Nov 30, 2025Updated 5 months ago
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application a…☆167Oct 28, 2025Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆193Apr 16, 2025Updated last year
- A simple touchID prompt'er for use in shell scripts.☆98Jun 18, 2024Updated last year
- A simple mitmproxy blueprint to intercept HTTPS traffic from app running on Kubernetes☆75Apr 14, 2025Updated last year
- A powerful containerized tool that automatically downloads, extracts, and scans packages from PyPI and npm for embedded secrets, API keys…☆20Jul 25, 2025Updated 9 months ago
- Autonomous AI C2☆33Jul 23, 2024Updated last year
- Enumeration/exploit/analysis/download/etc pentesting framework for GCP; modeled like Pacu for AWS; a product of numerous hours via @Webbi…☆298May 18, 2026Updated last week
- Halberd : Multi-Cloud Agentic Attack Tool☆337Apr 8, 2026Updated last month
- ☆18Jul 30, 2024Updated last year
- Read Chromium data (namely, cookies and local storage) straight from disk, without spinning up the browser.☆138May 7, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows☆124May 18, 2026Updated last week
- 🧰 Multi Tool Kubernetes Pentest Image☆258Mar 30, 2026Updated last month
- ☆40Aug 2, 2024Updated last year
- Modular web-application honeypot platform built using go and gin☆63May 8, 2024Updated 2 years ago
- Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI☆1,301May 4, 2026Updated 3 weeks ago
- A blazing-fast, thread-safe, straightforward and zero memory allocations tool to swiftly generate alternative IP(v4) address representati…☆93Aug 25, 2023Updated 2 years ago
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆63Jan 25, 2025Updated last year
- Azure DevOps Services Attack Toolkit☆315Mar 15, 2025Updated last year
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆59Sep 20, 2023Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆72Oct 24, 2025Updated 7 months ago
- A tool for quickly evaluating IAM permissions in AWS.☆60Nov 6, 2023Updated 2 years ago
- Okta Verify and Okta FastPass Abuse Tool☆343Sep 4, 2024Updated last year
- Automation tool for Windows Deception Host Burn-In☆85Dec 4, 2024Updated last year
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens☆165Nov 29, 2024Updated last year
- Daily updates from leaked data search engines, aggregators and similar services.☆168Updated this week
- Independently deploy customized honeyservices in AWS to trigger alerts on unauthorized access. It utilizes a dedicated CloudTrail for pre…☆52Nov 16, 2024Updated last year
- ☆571Mar 28, 2024Updated 2 years ago
- Utilities for Pentesting with BloodHound☆23Updated this week
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Identify hardcoded secrets in static structured text (version 2)☆98Feb 5, 2025Updated last year
- .NET deserialization hunter☆91Jul 21, 2024Updated last year
- Slides and Codes used for the workshop Red Team Infrastructure Automation☆193Apr 14, 2024Updated 2 years ago
- Ivanti Connect Secure IFT TLS Stack Overflow pre-auth RCE (CVE-2025-0282)☆31Jan 18, 2025Updated last year
- Search for sensitive data in Postman public library.☆212Aug 28, 2025Updated 8 months ago
- Use AI to Scan Your Code from the Command Line for security and code smells. Bring your own keys. Supports OpenAI and Gemini☆175Apr 23, 2025Updated last year
- ☆18Apr 24, 2026Updated last month