detectify / ugly-ducklingLinks
Ugly Duckling is a lightweight scanner built specifically for our Crowdsource community to submit proof-of-concept modules
☆189Updated 3 years ago
Alternatives and similar repositories for ugly-duckling
Users that are interested in ugly-duckling are comparing it to the libraries listed below
Sorting:
- Weaponizing Live CT logs for automated monitoring of assets☆134Updated 3 years ago
- Adds a customizable "Send to..."-context-menu to your BurpSuite.☆161Updated 2 years ago
- ☆71Updated 4 years ago
- A Burp Suite Extension for parsing Project Files from the CLI.☆87Updated 9 months ago
- ☆108Updated 4 years ago
- ASN reconnaissance script☆127Updated last year
- xss development frameworks, with the goal of making payload writing easier.☆143Updated 11 months ago
- Cross Origin Resource Sharing MisConfiguration Scanner☆173Updated 3 years ago
- Custom scripts for the PIPER Burp extensions.☆98Updated last year
- DNS and Target HTTP History Local Storage and Search☆64Updated 4 years ago
- ☆68Updated 3 years ago
- The Burp extension to check JWT (JSON Web Tokens) for using keys from known from public sources☆134Updated 4 years ago
- GoFingerprint is a Go tool for taking a list of target web servers and matching their HTTP responses against a user defined list of fing…☆202Updated 2 years ago
- ☆72Updated 3 years ago
- GraphQL security workshop labs☆112Updated this week
- A simple way of sending messages from the CLI output to your Slack with webhook.☆115Updated last year
- Takeover subdomains using AWS dangling elastic ips and have a working POC for Subdomain Takeover.☆92Updated this week
- A tool geared towards pentesting APIs using OpenAPI definitions.☆177Updated 2 years ago
- A blazing fast & feature rich Amazon S3 bucket enumerator.☆98Updated 2 years ago
- Searching for virtual hosts among non-resolvable domains☆88Updated 5 years ago
- ☆76Updated 4 years ago
- Detectify Crowdsource Challenge☆69Updated 3 years ago
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆65Updated 4 years ago
- An open source tool to aid in command line driven generation of bug bounty reports based on user provided templates.☆211Updated 4 years ago
- Bucky (An automatic S3 bucket discovery tool)☆197Updated 3 years ago
- Prototype pollution scanner using headless chrome☆219Updated 2 years ago
- You can read the writeup on this script here☆193Updated 3 years ago
- GraphQL security testing tool☆122Updated 3 years ago
- Bass grabs you those "extra resolvers" you are missing out on when performing Active DNS enumeration. Add anywhere from 100-6k resolvers …☆147Updated last year
- Retrieve the complete build history for every job ever created and executed on a given Jenkins instance.☆67Updated 2 months ago