The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2.0 Service Providers, also supporting SCIM protocol.
☆65Jul 23, 2026Updated last month
Alternatives and similar repositories for maSSO
Users that are interested in maSSO are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An extension to find callback endpoints in the background while searching the Web☆48Mar 26, 2026Updated 5 months ago
- Blogpost series showcasing interesting cloud - web app security bugs☆76Jul 20, 2026Updated last month
- Detect the cloud / hosting provider of a given host. Fast, static & offline☆16Updated this week
- A Burp Suite extension for Lightning/Aura framework security testing with advanced action management, context editing, and comprehensive …☆68Mar 2, 2026Updated 6 months ago
- Burp plugin for jxscout☆25May 12, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traff…☆13Aug 14, 2026Updated 3 weeks ago
- Burp Suite MCP Assistant in IDE Extension☆15Dec 31, 2025Updated 8 months ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- 0xJS is an AI-powered JavaScript Security Tool☆67Apr 16, 2026Updated 4 months ago
- Advanced test for proxy & waf☆13Feb 10, 2026Updated 7 months ago
- My Main App Hacking CheckList☆35Jun 20, 2026Updated 2 months ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆184Updated this week
- ☆48Sep 21, 2025Updated 11 months ago
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆29Jun 16, 2026Updated 2 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- This plugin is inspired by tools.slcyber.io. It contains two tools: Surf (an SSRF target discovery tool) and Wordlists (custom wordlists …☆25Jan 19, 2026Updated 7 months ago
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated 2 months ago
- ☆27Jun 6, 2026Updated 3 months ago
- Library of Exploiting Last Frame Synchronization (also know as Single Packet Attack) on HTTP/3 - Manipulated version of quic-go lib☆20Updated this week
- SSRFHunter☆18Jan 17, 2026Updated 7 months ago
- Caido plugin to send HTTP requests to external CLI security tools with preview, batch execution, and live output☆24Aug 20, 2026Updated 3 weeks ago
- An application for distributing oclHashcat tasks.☆21Nov 19, 2015Updated 10 years ago
- this is everything☆44Apr 7, 2026Updated 5 months ago
- ☆51Aug 2, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Regex patterns for manual application source code review☆34Dec 14, 2020Updated 5 years ago
- A python script to automatically dump files and source code of a Symfony server in debug mode.☆13Updated this week
- Exploit for CVE-2024-0402 in Gitlab☆15Mar 18, 2025Updated last year
- A tool to extract and dump files of mercurial SCM exposed on a web server.☆13Jan 31, 2025Updated last year
- Enhanced Burp Suite extension for finding links and sensitive data in JavaScript files☆26May 10, 2026Updated 4 months ago
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆127Updated this week
- Dependency Confusion Security Testing Tool☆50Jul 21, 2022Updated 4 years ago
- PoC's and Slides from 'Gophers, whales and.. clouds? Oh my!' BSides Wellington presentation by Glenn 'devalias' Grant☆17Mar 3, 2018Updated 8 years ago
- ☆46May 12, 2025Updated last year
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Repro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!☆21Aug 25, 2024Updated 2 years ago
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 5 months ago
- ☆57Jun 28, 2026Updated 2 months ago
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆34May 28, 2026Updated 3 months ago
- Demonstrate how a signed driver can bypass defenses to deploy ransomware on Windows 11 with advanced AV and UAC evasion techniques.☆34Updated this week
- Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.☆22Apr 2, 2026Updated 5 months ago
- Burp Suite extension — passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, ent…☆54Aug 24, 2026Updated 2 weeks ago