PortSwigger / paramalyzerLinks
Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.
☆33Updated 2 years ago
Alternatives and similar repositories for paramalyzer
Users that are interested in paramalyzer are comparing it to the libraries listed below
Sorting:
- A GraphQL enumeration and extraction tool☆133Updated 2 years ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆53Updated last year
- ☆90Updated 3 years ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆72Updated 3 years ago
- Additional active scan checks for BURP☆28Updated 11 months ago
- spk aka spritzgebaeck: A small OSINT/Recon tool to find CIDRs that belong to a specific organization.☆84Updated 3 months ago
- cvet is a Python utility for pulling actionable vulnerabilities from cvetrends.com☆39Updated 3 years ago
- HazProne is a Cloud Pentesting Framework that emulates close to Real-World Scenarios by deploying Vulnerable-By-Demand AWS resources enab…☆40Updated 3 years ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆33Updated 6 months ago
- A very vulnerable implementation of a GraphQL API.☆61Updated 3 years ago
- A collection of BBRF agents that can be deployed to AWS lambda☆23Updated 10 months ago
- Jumpstart multiple WebSocket servers quickly☆31Updated 3 years ago
- An extension to use Semgrep inside Burp Suite.☆89Updated 3 months ago
- Most common AWS S3 bucket names.☆27Updated 5 years ago
- A tool for check available dependency packages across npmjs, PyPI or RubyGems registry.☆30Updated 3 years ago
- A collection of my Semgrep rules☆49Updated 2 years ago
- Target practice for ffuf☆67Updated 4 years ago
- Take domains on stdin and output them on stdout if they get resolved☆33Updated 3 years ago
- Python's handling of NaN is....interesting?broken?...this project illustrates the issue☆13Updated 3 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆30Updated 2 years ago
- Ffuf output browser☆39Updated 2 years ago
- 🚀 Sling Shot R3con: Automate Your Bug Bounty and Pentest Reconnaissance with Project Discovery tools 🎯☆25Updated 2 years ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆76Updated 3 years ago
- Create your own recon & vulnerability scanner with Trickest and GitHub☆49Updated last year
- Monitoring the Cloud Landscape☆87Updated this week
- Simple PoC for demonstrating Race Conditions on Websockets☆55Updated 2 years ago
- The wordlists that have been compiled using disclosed reports at HackerOne bug bounty platform☆59Updated 5 years ago
- An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.☆44Updated 8 months ago
- Dependency Confusion Security Testing Tool☆50Updated 3 years ago
- A python3 script searching for secret on swaggerhub☆68Updated 3 years ago