PortSwigger / attack-surface-detectorLinks
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
☆14Updated 3 years ago
Alternatives and similar repositories for attack-surface-detector
Users that are interested in attack-surface-detector are comparing it to the libraries listed below
Sorting:
- An AWS Lambda vulnerable application written in flask.☆48Updated 7 years ago
- Pivot into private VPC networks using a VPN connection☆43Updated 5 years ago
- Tools for auditing WAFS☆19Updated 3 years ago
- Scripts that we use for pentesting☆42Updated 8 years ago
- ☆29Updated 8 years ago
- ☆24Updated last year
- Unofficial api for cve.mitre.org☆40Updated 3 years ago
- Kubernetes Scanner☆40Updated 3 years ago
- ☆36Updated 5 years ago
- ☆25Updated 4 years ago
- Simple trick to increase readability of exceptions raised by Burp extensions written in Python☆44Updated 8 years ago
- Burp Extension for AWS Signing☆89Updated 6 months ago
- The SSH Multiplex Backdoor Tool☆63Updated 5 years ago
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- Docker Version of Aquatone☆14Updated 7 years ago
- Clickjacking PoC Generator☆35Updated 4 years ago
- Helper scripts to assist penetration testing and exploit development☆36Updated 7 months ago
- Simple S3 Bucket Testing Software☆31Updated 3 years ago
- This is a set of tips and reminders for pentesting processes and scripts/programs. Initially for personal use, but if anyone else finds t…☆52Updated 5 years ago
- Terraform configuration to build a Burp Private Collaborator Server☆29Updated 6 years ago
- Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding In…☆18Updated 4 years ago
- An enumeration and exploitation toolkit using RFC calls to SAP☆38Updated 5 years ago
- A multi-processed, multi-threaded scanner to discover web directories on multiple URLs.☆21Updated 5 years ago
- Burp as a Docker Container☆59Updated 4 years ago
- List (or plunder) private repos/gists to which a token has access, including those of other users☆11Updated 3 years ago
- Interactsh deployment to AWS EC2 Instance with Terraform☆12Updated 3 years ago
- Zone transfers for rwhois☆20Updated 6 years ago
- Slides of the talk on Injection attacks in apps with NoSQL Backends, given at null OWASP Bangalore monthly meet on 27th April 2019☆22Updated 6 years ago
- ☆20Updated 5 years ago
- NMAP NSE script that scans for http(s) server, takes a screenshot of them, and organizes the results into an HTML report.☆27Updated 10 years ago