The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2.0 Service Providers, also supporting SCIM protocol.
☆60Jul 23, 2026Updated last week
Alternatives and similar repositories for maSSO
Users that are interested in maSSO are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An extension to find callback endpoints in the background while searching the Web☆47Mar 26, 2026Updated 4 months ago
- Blogpost series showcasing interesting cloud - web app security bugs☆75Jul 20, 2026Updated 2 weeks ago
- Detect the cloud / hosting provider of a given host. Fast, static & offline☆15Updated this week
- A Burp Suite extension for Lightning/Aura framework security testing with advanced action management, context editing, and comprehensive …☆67Mar 2, 2026Updated 5 months ago
- Burp plugin for jxscout☆23May 12, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Burp Suite MCP Assistant in IDE Extension☆15Dec 31, 2025Updated 7 months ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- 0xJS is an AI-powered JavaScript Security Tool☆66Apr 16, 2026Updated 3 months ago
- Advanced test for proxy & waf☆14Feb 10, 2026Updated 5 months ago
- My Main App Hacking CheckList☆33Jun 20, 2026Updated last month
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆169Updated this week
- ☆47Sep 21, 2025Updated 10 months ago
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆26Jun 16, 2026Updated last month
- This plugin is inspired by tools.slcyber.io. It contains two tools: Surf (an SSRF target discovery tool) and Wordlists (custom wordlists …☆23Jan 19, 2026Updated 6 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated last month
- ☆26Jun 6, 2026Updated last month
- Library of Exploiting Last Frame Synchronization (also know as Single Packet Attack) on HTTP/3 - Manipulated version of quic-go lib☆20Jun 23, 2026Updated last month
- SSRFHunter☆18Jan 17, 2026Updated 6 months ago
- ☆51Aug 2, 2025Updated last year
- EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.☆69May 11, 2026Updated 2 months ago
- Caido plugin to send HTTP requests to external CLI security tools with preview, batch execution, and live output☆23Jun 29, 2026Updated last month
- An application for distributing oclHashcat tasks.☆21Nov 19, 2015Updated 10 years ago
- this is everything☆41Apr 7, 2026Updated 3 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Regex patterns for manual application source code review☆34Dec 14, 2020Updated 5 years ago
- A python script to automatically dump files and source code of a Symfony server in debug mode.☆13Feb 11, 2025Updated last year
- Exploit for CVE-2024-0402 in Gitlab☆15Mar 18, 2025Updated last year
- Burp Suite extension that extends Burp to support storing and reusing variables in requests☆30Feb 10, 2026Updated 5 months ago
- A tool to extract and dump files of mercurial SCM exposed on a web server.☆13Jan 31, 2025Updated last year
- Enhanced Burp Suite extension for finding links and sensitive data in JavaScript files☆26May 10, 2026Updated 2 months ago
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆115Updated this week
- Dependency Confusion Security Testing Tool☆50Jul 21, 2022Updated 4 years ago
- PoC's and Slides from 'Gophers, whales and.. clouds? Oh my!' BSides Wellington presentation by Glenn 'devalias' Grant☆17Mar 3, 2018Updated 8 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆46May 12, 2025Updated last year
- Repro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!☆21Aug 25, 2024Updated last year
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- ☆56Jun 28, 2026Updated last month
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆33May 28, 2026Updated 2 months ago
- Demonstrate how a signed driver can bypass defenses to deploy ransomware on Windows 11 with advanced AV and UAC evasion techniques.☆32Jul 27, 2026Updated last week
- Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.☆22Apr 2, 2026Updated 4 months ago