MCP Attack Surface Detector - Burp plugin to make manual testing of MCP servers easier in Burp Suite
☆31Feb 26, 2026Updated 5 months ago
Alternatives and similar repositories for MCP-ASD
Users that are interested in MCP-ASD are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Give me your APK, I will give you framework name☆15May 6, 2026Updated 3 months ago
- Burp Suite MCP Assistant in IDE Extension☆15Dec 31, 2025Updated 7 months ago
- ☆21Dec 8, 2022Updated 3 years ago
- The Java Burp Extension version of my BypassFuzzer tool☆36Updated this week
- Android security tool that scans installed apps bytecode to discover content providers, file providers, and intent interfaces, then gener…☆18Mar 12, 2026Updated 4 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A Burp extension to Fuzz URLs for HTTP parser inconsistencies☆15Jan 9, 2024Updated 2 years ago
- Helper script for BloodHound to automatically add relationships between multiple accounts owned by the same individual☆15Jul 13, 2022Updated 4 years ago
- BurpSuite Extension for performing scan via CLI.☆15Dec 5, 2017Updated 8 years ago
- Kibana app for RedELK☆18Mar 19, 2023Updated 3 years ago
- An extension for Burp's Web Vulnerability Scanner that can detect API discovery metadata and extract data useful during recon.☆19Sep 13, 2025Updated 10 months ago
- A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.☆134Mar 30, 2026Updated 4 months ago
- 一款集成了Nuclei模板管理、多空间引擎搜索的网络安全工具集。为安全研究人员提供高效的工作体验。☆23Mar 16, 2026Updated 4 months ago
- A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.☆26Apr 20, 2026Updated 3 months ago
- ☆29Mar 24, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Impacket with --remove-mic-partial☆49Jan 8, 2026Updated 7 months ago
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information i…☆17Apr 13, 2026Updated 3 months ago
- ☆37Jul 30, 2026Updated last week
- 🔐🚀 Professional Burp Suite extension for 5G Core security testing 📡 | Automated NF discovery 🔍 | IMSI enumeration 📱 | Credential ext…☆21Dec 1, 2025Updated 8 months ago
- Utility for ClickOnce usage for Red Teams.☆15Jun 11, 2026Updated last month
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated last month
- PowerShell tool for auditing Microsoft Entra ID Conditional Access policies and MFA compliance☆45Aug 2, 2025Updated last year
- CVE-2025-59501 POC code☆25Nov 20, 2025Updated 8 months ago
- Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID☆180Jul 10, 2026Updated 3 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- PowerShell implementation for AD CS☆159Jul 30, 2026Updated last week
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 7 months ago
- surface-watch monitors the authorized external attack surface of an organization over time☆56May 11, 2026Updated 2 months ago
- MDE/MDI Defender setup for Ludus☆62Jul 30, 2026Updated last week
- Imperial Security Reconnaissance System☆25Feb 10, 2026Updated 5 months ago
- Red Team Coin for crypto-mining operations.☆25Mar 1, 2026Updated 5 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆106Apr 4, 2026Updated 4 months ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- HoneyZure is a honeypot tool specifically designed for Azure environments, fully provisioned through Terraform. It leverages a Log Analyt…☆17Jun 11, 2024Updated 2 years ago
- PoC: process watcher patterns to make killing a process hard.☆11Aug 1, 2018Updated 8 years ago
- ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets …☆163Jul 8, 2026Updated last month
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆176Updated this week
- Terraform-deployable Azure security lab with intentionally vulnerable resources for learning and practicing attack paths in your own tena…☆37Jul 24, 2026Updated 2 weeks ago
- Scripts to interact with Microsoft Graph APIs☆46Nov 7, 2024Updated last year
- Tailscale/Headscale C2 profile and agent for Mythic☆25Mar 14, 2026Updated 4 months ago