PortSwigger / asset-discoveryLinks
Burp Suite extension to discover assets from HTTP response.
☆16Updated 4 years ago
Alternatives and similar repositories for asset-discovery
Users that are interested in asset-discovery are comparing it to the libraries listed below
Sorting:
- Burp extension that checks application requests and responses for indicators of vulnerability or targets for attack☆41Updated 2 years ago
- Nmap script to check vulnerability CVE-2021-21975☆28Updated 4 years ago
- The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.☆76Updated 4 years ago
- Kubernetes Scanner☆40Updated 3 years ago
- Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities☆46Updated 2 years ago
- This is the Go Server that relays all HTTP requests and responses between clients.☆27Updated last year
- Image Tragick Exploit Tool Using Burp Collaborator☆36Updated last year
- ☆36Updated 5 months ago
- RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2☆60Updated 4 years ago
- Local File Inclusion Burp-Suite Intruder Payload Generator Plugin☆40Updated 4 years ago
- A bash script that automates the scanning of a target network for HTTP resources through XXE☆38Updated 4 years ago
- Reconnaisance Tool☆11Updated 5 years ago
- Hacked together script for feeding urls into Burp's Sitemap☆93Updated 2 months ago
- A simple tool to detect wildcards domain based on Amass's wildcards detector.☆65Updated 4 years ago
- CVE-2020-9484 Mass Scanner, Scan a list of urls for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE☆32Updated 5 years ago
- A Web-UI for subdomain enumeration (subfinder)☆54Updated 5 years ago
- ☆47Updated 4 years ago
- Add headers to all Burp requests to bypass some WAF products☆42Updated last year
- Collection of scanner checks missing in Burp☆31Updated 5 years ago
- Burp Extension that lets you use Burp Collaborator as a DNS server for exfiltrating data via Sqlmap☆36Updated 3 years ago
- The original slurp source☆33Updated 6 years ago
- Spring Boot Actuator (jolokia) XXE/RCE☆22Updated 6 years ago
- Get all possible href | src | url from target url or domain☆41Updated 4 years ago
- SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing☆91Updated 5 years ago
- Writeup of CVE-2020-15906☆48Updated 4 years ago
- Dump exposed HTTP .git fast☆50Updated 2 years ago
- Unique wordlist generator of unique wordlists.☆42Updated last year
- All in one port scanning script.☆68Updated 5 years ago
- JavaScript functions intended to be used as an XSS payload against a WordPress admin account.☆54Updated 4 years ago
- Finds Directory Listings or open S3 buckets from a list of URLs☆53Updated 3 years ago