PortSwigger / paramalyzerLinks
Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.
☆34Updated 3 years ago
Alternatives and similar repositories for paramalyzer
Users that are interested in paramalyzer are comparing it to the libraries listed below
Sorting:
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Updated last year
- ☆90Updated 3 years ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆73Updated 3 years ago
- An extension to use Semgrep inside Burp Suite.☆89Updated 8 months ago
- ☆33Updated last year
- Jumpstart multiple WebSocket servers quickly☆31Updated 4 years ago
- A GraphQL enumeration and extraction tool☆134Updated 3 years ago
- ☆29Updated 3 years ago
- Monitoring the Cloud Landscape☆91Updated last week
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆31Updated 2 years ago
- Ffuf output browser☆40Updated 2 years ago
- A very vulnerable implementation of a GraphQL API.☆61Updated 4 years ago
- Simple PoC for demonstrating Race Conditions on Websockets☆55Updated 2 years ago
- Additional active scan checks for BURP☆28Updated last year
- Create your own recon & vulnerability scanner with Trickest and GitHub☆48Updated 2 years ago
- spk aka spritzgebaeck: A small OSINT/Recon tool to find CIDRs that belong to a specific organization.☆84Updated 2 weeks ago
- ☆24Updated 3 years ago
- Let's check if your target is vulnerable for client side prototype pollution.☆65Updated 2 years ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆76Updated 3 years ago
- A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabiliti…☆119Updated 2 years ago
- 🚀 Sling Shot R3con: Automate Your Bug Bounty and Pentest Reconnaissance with Project Discovery tools 🎯☆25Updated 2 years ago
- ☆38Updated 4 years ago
- HazProne is a Cloud Pentesting Framework that emulates close to Real-World Scenarios by deploying Vulnerable-By-Demand AWS resources enab…☆40Updated 3 years ago
- security.txt collection of most popular world-wide domains☆55Updated 2 years ago
- Dependency Confusion Security Testing Tool☆51Updated 3 years ago
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆52Updated 3 years ago
- Security Advisories☆35Updated 2 months ago
- My talks...☆25Updated 11 months ago
- swagroutes is a command-line tool that extracts and lists API routes from Swagger files in YAML or JSON format.☆61Updated 2 years ago
- A custom built DNS bruteforcer with multi-threading, and handling of bad resolvers.☆57Updated 3 years ago