PortSwigger / paramalyzer
Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.
☆32Updated 2 years ago
Alternatives and similar repositories for paramalyzer:
Users that are interested in paramalyzer are comparing it to the libraries listed below
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆51Updated 4 months ago
- ☆21Updated 7 years ago
- Additional active scan checks for BURP☆26Updated 3 months ago
- Ffuf output browser☆39Updated last year
- ☆90Updated 2 years ago
- Python's handling of NaN is....interesting?broken?...this project illustrates the issue☆13Updated 3 years ago
- swagroutes is a command-line tool that extracts and lists API routes from Swagger files in YAML or JSON format.☆56Updated last year
- cvet is a Python utility for pulling actionable vulnerabilities from cvetrends.com☆39Updated 2 years ago
- ☆25Updated 2 years ago
- Jumpstart multiple WebSocket servers quickly☆31Updated 3 years ago
- Mole is a framework for identifying and exploiting out-of-band application vulnerabilities.☆57Updated 4 years ago
- ☆58Updated last year
- An extension to use Semgrep inside Burp Suite.☆88Updated last year
- Manage attack surface data on Elasticsearch☆21Updated last year
- Script to automate, when possible, the passive reconnaissance performed on a website prior to an assessment.☆37Updated 3 weeks ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆67Updated 2 years ago
- A collection of one off hacks and simple scripts☆28Updated last year
- Simple PoC for demonstrating Race Conditions on Websockets☆56Updated last year
- A collection of my Semgrep rules☆48Updated last year
- ☆22Updated 2 years ago
- Create your own recon & vulnerability scanner with Trickest and GitHub☆49Updated last year
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆21Updated last month
- ☆51Updated last month
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆28Updated 2 weeks ago
- Contains all my research and content produced regarding the log4shell vulnerability☆31Updated 3 years ago
- HazProne is a Cloud Pentesting Framework that emulates close to Real-World Scenarios by deploying Vulnerable-By-Demand AWS resources enab…☆39Updated 2 years ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆31Updated last year
- OWASP Foundation Web Respository☆35Updated 3 years ago
- ☆27Updated last year
- The Template Injection Playground allows to test a large number of the most relevant template engines for template injection possibilitie…☆25Updated 8 months ago