PortSwigger / paramalyzerLinks
Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.
☆34Updated 3 years ago
Alternatives and similar repositories for paramalyzer
Users that are interested in paramalyzer are comparing it to the libraries listed below
Sorting:
- A GraphQL enumeration and extraction tool☆133Updated 2 years ago
- ☆90Updated 3 years ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Updated last year
- Dependency Confusion Security Testing Tool☆51Updated 3 years ago
- Additional active scan checks for BURP☆28Updated last year
- A collection of BBRF agents that can be deployed to AWS lambda☆23Updated last year
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆73Updated 3 years ago
- The wordlists that have been compiled using disclosed reports at HackerOne bug bounty platform☆58Updated 5 years ago
- An extension to use Semgrep inside Burp Suite.☆89Updated 6 months ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆34Updated 9 months ago
- Create your own recon & vulnerability scanner with Trickest and GitHub☆48Updated 2 years ago
- Target practice for ffuf☆69Updated 4 years ago
- A collection of utilities for building extensions using Burp's Montoya API☆52Updated last month
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆30Updated 2 years ago
- Monitoring the Cloud Landscape☆91Updated this week
- ☆38Updated 4 years ago
- Execute Trickest workflows right from your terminal☆94Updated 2 weeks ago
- A very vulnerable implementation of a GraphQL API.☆61Updated 4 years ago
- A collection of my Semgrep rules☆50Updated 2 years ago
- Let's check if your target is vulnerable for client side prototype pollution.☆65Updated last year
- Unicode Security Toolkit☆40Updated last year
- A Burp Suite extension for finding DNS vulnerabilities in web applications!☆94Updated 2 years ago
- 🚀 Sling Shot R3con: Automate Your Bug Bounty and Pentest Reconnaissance with Project Discovery tools 🎯☆25Updated 2 years ago
- spk aka spritzgebaeck: A small OSINT/Recon tool to find CIDRs that belong to a specific organization.☆84Updated 6 months ago
- A custom built DNS bruteforcer with multi-threading, and handling of bad resolvers.☆57Updated 3 years ago
- ☆95Updated 4 years ago
- ☆28Updated 2 years ago
- ☆32Updated last year
- Make better use of the embedded browser that comes by default with Burp☆45Updated last year
- Jumpstart multiple WebSocket servers quickly☆32Updated 4 years ago