A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities
☆122Nov 23, 2023Updated 2 years ago
Alternatives and similar repositories for pentest-mapper
Users that are interested in pentest-mapper are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆32Jun 22, 2023Updated 3 years ago
- ☆22Oct 9, 2017Updated 8 years ago
- Automatic Bug finder with buprsuite☆167Mar 6, 2023Updated 3 years ago
- A burpsuite extension that helps security researchers find public security reports published on h1 based on the selected host☆43May 9, 2020Updated 6 years ago
- This extension provides a way to discover NoSQL injection vulnerabilities.☆11Feb 1, 2021Updated 5 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- BurpSiute - BurpBounty Profiles☆20Feb 10, 2023Updated 3 years ago
- ☆19Jan 24, 2023Updated 3 years ago
- Burp extension to check and exploit the IIS Tilde Enumeration/IIS 8.3 Short Filename Disclosure vulnerability☆62Jun 12, 2023Updated 3 years ago
- A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.☆184Nov 22, 2021Updated 4 years ago
- Find known vulnerabilities in WordPress plugins and themes using Burp Suite proxy. WPScan like plugin for Burp.☆76Feb 25, 2022Updated 4 years ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆267Mar 4, 2023Updated 3 years ago
- Attack Active Directory Trusts with a single tool☆14Jan 15, 2025Updated last year
- This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.☆247Mar 17, 2025Updated last year
- Apache HTTP-Server 2.4.49-2.4.50 Path Traversal & Remote Code Execution PoC (CVE-2021-41773 & CVE-2021-42013)☆13Aug 22, 2025Updated 11 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist☆1,523Jan 8, 2026Updated 6 months ago
- A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues☆379Jul 25, 2023Updated 3 years ago
- This repository is for the Testing ASP.NET ViewState with YSoNet (YSoSerial.NET) workshop.☆25Dec 17, 2025Updated 7 months ago
- Nuclei plugin for BurpSuite☆1,340Oct 22, 2025Updated 9 months ago
- ☆125May 8, 2024Updated 2 years ago
- Active Directory share enumeration tool☆13Apr 28, 2025Updated last year
- A tech enumeration toolkit focused on 404 Not found pages.☆29Oct 6, 2024Updated last year
- It becomes the extension of Burp suite. The cookie set by the BipIP server may include a private IP, which is an extension to detect tha…☆16Mar 10, 2026Updated 4 months ago
- vulnerable OAuth 2.0 applications: understand the security implications of your OAuth 2.0 decisions.☆332Mar 27, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Python resource library for creating security related tooling☆77Jul 11, 2024Updated 2 years ago
- A fork of Space Station 14, embracing a mixture of classic SS13 chaos and experimentation only possible with the new engine☆12Oct 27, 2023Updated 2 years ago
- Obtain GraphQL API schema despite disabled introspection!☆69Mar 11, 2026Updated 4 months ago
- Zed Attack Proxy Scripts for finding CVEs and Secrets.☆126Jun 2, 2022Updated 4 years ago
- A rapid HTTP downgrade smuggling scanner written in Go.☆314May 16, 2024Updated 2 years ago
- ☆61Apr 6, 2026Updated 3 months ago
- Tool for testing reflections in the HTTP responses☆60Jun 10, 2023Updated 3 years ago
- A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabiliti…☆119Aug 2, 2023Updated 2 years ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆756Jul 10, 2026Updated 2 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆192Dec 3, 2024Updated last year
- APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is int…☆972Jan 17, 2025Updated last year
- Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned ent…☆2,223Feb 23, 2026Updated 5 months ago
- SSRF plugin for burp Automates SSRF Detection in all of the Request☆630Jan 20, 2021Updated 5 years ago
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets☆1,575Mar 8, 2026Updated 4 months ago
- A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomain…☆904May 3, 2023Updated 3 years ago
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the ac…☆1,808Apr 26, 2024Updated 2 years ago