PortSwigger / attack-surface-detectorLinks
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
☆14Updated 3 years ago
Alternatives and similar repositories for attack-surface-detector
Users that are interested in attack-surface-detector are comparing it to the libraries listed below
Sorting:
- Burp Extension for AWS Signing☆90Updated last year
- An AWS Lambda vulnerable application written in flask.☆49Updated 8 years ago
- WStalker: an easy proxy☆25Updated 5 years ago
- Alphanumeric Encoder☆25Updated 7 years ago
- Scripts that we use for pentesting☆42Updated 8 years ago
- ☆29Updated 9 years ago
- Simple trick to increase readability of exceptions raised by Burp extensions written in Python☆45Updated 8 years ago
- ☆36Updated 5 years ago
- This is a Burpsuite plugin built to enable you to import your directory bruteforcing results into burp for easy viewing later. This is an…☆36Updated 2 years ago
- Zone transfers for rwhois☆20Updated 6 years ago
- An Evil OIDC Server☆54Updated 3 years ago
- This is a set of tips and reminders for pentesting processes and scripts/programs. Initially for personal use, but if anyone else finds t…☆52Updated 5 years ago
- OAuth Security Cheatsheet☆40Updated 11 years ago
- Salesforce Policy Deviation Checker☆30Updated 5 years ago
- API testing tool written with Python☆56Updated 8 years ago
- Kubernetes Scanner☆40Updated 3 years ago
- Capture all RabbitMQ messages being sent through a broker.☆32Updated 4 years ago
- Pivot into private VPC networks using a VPN connection☆43Updated 6 years ago
- Notes as I learn basic AWS penetration testing☆67Updated 6 years ago
- This repo gives an overview of some GCP metadata API attack and defend patterns☆78Updated 5 years ago
- NMAP NSE script that scans for http(s) server, takes a screenshot of them, and organizes the results into an HTML report.☆27Updated 11 years ago
- A simple remote scanner for Liferay Portal☆20Updated 9 months ago
- Jekyll Files for cloudsecwiki.com☆49Updated 4 years ago
- Endpoint for Out-of-Band Exfiltration (DNS & HTTP)☆93Updated 7 years ago
- A tool for auditing medical devices and healthcare infrastructure☆22Updated 2 weeks ago
- An auxiliary spellcheck dictionary that corresponds with the Bishop Fox Cybersecurity Style Guide☆94Updated 2 years ago
- Report and finding templates used by the Serpico reporting tool☆16Updated 7 years ago
- Collection of Semgrep rules for security analysis☆10Updated last year
- This extension provide a Python panel for writing custom proxy script.☆16Updated 6 years ago
- A combined list of helpful awscli commands from Scott Piper's flaws.cloud exercise as well as from Beau Bullock's Breaching the Cloud Tra…☆19Updated 4 years ago