PortSwigger / get-all-parametersLinks
Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist
☆27Updated last month
Alternatives and similar repositories for get-all-parameters
Users that are interested in get-all-parameters are comparing it to the libraries listed below
Sorting:
- BChecks collection for Burp Suite Professional☆102Updated last year
- ☆138Updated last year
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆103Updated 2 years ago
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆158Updated last year
- Go scanner to find web cache poisoning vulnerabilities in a list of URLs☆149Updated last year
- ☆110Updated last year
- ☆129Updated 4 years ago
- Golang tool which helps dropping the irrelevant entries from your ffuf result file.☆141Updated last year
- A path-normalization pentesting tool.☆150Updated 3 weeks ago
- Identify virtual hosts by similarity comparison☆134Updated last year
- A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs☆75Updated 8 months ago
- ☆157Updated 2 years ago
- A subdomain fuzzing tool☆172Updated last year
- jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice☆290Updated last year
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆81Updated 2 years ago
- A plugin for Burp Suite Pro that uses the GraphQL schema to begin Active Scanning the entire endpoint.☆41Updated 3 months ago
- JSSCM detects expired domains for Stored XSS exploitation during browsing.☆58Updated 10 months ago
- ☆249Updated 4 years ago
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆148Updated last year
- Simplify your life with leak detection in JavaScript. NipeJS streamlines the use of regex, making it effortless to uncover potential leak…☆96Updated last year
- ☆46Updated last year
- A fast, minimalistic scanner for time-based SQL injection (SQLi) detection – built in Go.☆138Updated 9 months ago
- GQLSpection - parses GraphQL introspection schema and generates possible queries☆99Updated 11 months ago
- A comprehensive list of custom filters for Logger++ to identify various vulnerabilities in different API styles☆234Updated last year
- A rapid HTTP downgrade smuggling scanner written in Go.☆311Updated last year
- Burpsuite plugin for Interact.sh☆230Updated last year
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.☆37Updated 6 months ago
- ☆32Updated 2 years ago
- Check AWS S3 instances for read/write/delete access☆121Updated 4 years ago
- Filter and enrich a list of subdomains by level☆210Updated 2 years ago