This repository contains all the examples related to a series of tutorials that demonstrate how to use the new Montoya API of Burp Suite to create extensions that will greatly simplify our pentester lives.
☆53May 5, 2026Updated 4 months ago
Alternatives and similar repositories for Burp-Suite-Extender-Montoya-Course
Users that are interested in Burp-Suite-Extender-Montoya-Course are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A collection of utilities for building extensions using Burp's Montoya API☆52Apr 14, 2026Updated 5 months ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆38Mar 4, 2025Updated last year
- POC for leaking java version through file and ftp protocols☆24Nov 1, 2020Updated 5 years ago
- 针对IoT固件的openssl加密的暴力破解脚本☆13May 22, 2024Updated 2 years ago
- THC "R U There" network discovery tool☆31May 1, 2020Updated 6 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- by Gary O'Leary-Steele | cloned from https://sentinel.appcheck-ng.com/static/pm/logger.html☆12Sep 16, 2019Updated 7 years ago
- Prototype Pollution Lab☆18Nov 20, 2020Updated 5 years ago
- This Burp extension helps you to find usages of postMessage and recvMessage☆14Feb 20, 2020Updated 6 years ago
- ☆20Jul 14, 2025Updated last year
- Automated HTTP Request Repeating With Burp Suite☆38Apr 3, 2023Updated 3 years ago
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂☆120Dec 24, 2025Updated 8 months ago
- Make better use of the embedded browser that comes by default with Burp☆45Updated this week
- A Firefox Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆28Dec 9, 2024Updated last year
- ☆37Jun 21, 2024Updated 2 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- FETCH THE PASSWORD STRETCHER☆40Dec 8, 2022Updated 3 years ago
- The Outlook HTML Leak Test Project☆41May 12, 2018Updated 8 years ago
- Dockerfile for AFL++ and helpful other tools☆21May 5, 2020Updated 6 years ago
- Following OWASP TOP 10 (the top ten most critical web application security risk) I decided to build an XSS Scanner.☆12Dec 12, 2022Updated 3 years ago
- Creates and sends fake meeting invite☆78Apr 24, 2021Updated 5 years ago
- Leverages B64 chunks to split files and save to clipboard☆26Jul 30, 2026Updated last month
- Application Security Mind Maps☆12Apr 10, 2021Updated 5 years ago
- Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"☆358Oct 14, 2020Updated 5 years ago
- A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.☆16Oct 11, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ExtendedMacro - BurpSuite plugin providing extended macro functionality☆15Jan 13, 2021Updated 5 years ago
- ☆65Mar 10, 2026Updated 6 months ago
- Nuclei templates for drupal vulns... far from perfect☆18Jan 9, 2025Updated last year
- Sample exploits of common vulnerabilities in Java librarires☆27Dec 14, 2023Updated 2 years ago
- ☆38Jan 17, 2024Updated 2 years ago
- Let's check if your target is vulnerable for client side prototype pollution.☆65Jan 9, 2024Updated 2 years ago
- Alternative Mimikatz LSASS DUMPER☆14Apr 2, 2020Updated 6 years ago
- WebApp intentionally made vulnerable to Race Condition for practicing Race Condition☆25Feb 23, 2022Updated 4 years ago
- WebSocket REPL for pentesters☆238Jul 24, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- tetctf2020_amf_writeups☆20Jan 3, 2021Updated 5 years ago
- Token Tailor is a Burp Suite Community Edition extension that aims to simplify security testing by automating JWT renewal.☆38Sep 30, 2025Updated 11 months ago
- REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications☆1,375Aug 7, 2025Updated last year
- An extension to use Semgrep inside Burp Suite.☆90May 23, 2025Updated last year
- Patches needed to build VMware (Player and Workstation) host modules against recent kernels☆19Oct 14, 2025Updated 11 months ago
- Custom Trickest Workflows☆12Oct 26, 2023Updated 2 years ago
- A path-normalization pentesting tool.☆155Apr 2, 2026Updated 5 months ago