A collection of scripts to extend Burp Suite
☆142Apr 8, 2019Updated 7 years ago
Alternatives and similar repositories for burp-extensions
Users that are interested in burp-extensions are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Burp Suite Extensions☆13Oct 19, 2021Updated 4 years ago
- ☆33May 30, 2019Updated 7 years ago
- Manual JavaScript Linting is a Bug☆48Mar 6, 2021Updated 5 years ago
- Python script to give you subsets of the nmap "top-ports". For example, I want the 10th to 100th most common TCP ports. Spits out a comma…☆18Mar 8, 2020Updated 6 years ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆300Feb 12, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Wordlist to get files/ folders listed by the app that may expose passwords, sensitive file or folders☆22Jul 10, 2020Updated 6 years ago
- This changes the style of Burp Suite's Repeater tabs to help the testers☆29Jul 3, 2019Updated 7 years ago
- Smart ssrf scanner using different methods like parameter brute forcing in post and get...☆277Feb 11, 2021Updated 5 years ago
- Automated blind-xss search for Burp Suite☆283Oct 10, 2019Updated 6 years ago
- HTTP file upload scanner for Burp Proxy☆494Dec 25, 2023Updated 2 years ago
- BURP extension providing a set of values for the HTTP request "Host" header for the "BURP Intruder" in order to abuse virtual host resolu…☆61Oct 8, 2017Updated 8 years ago
- Web App bug hunting☆580Nov 26, 2025Updated 8 months ago
- A better version of my xssfinder tool - scans for different types of xss on a list of urls.☆189Aug 3, 2019Updated 7 years ago
- Tools and resources for web app hacking. The payloads.txt documents are a must have for your Burpsuite intruder payload armory. They've h…☆28Jun 10, 2019Updated 7 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- all manner of wordlists☆24Jan 19, 2022Updated 4 years ago
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the ac…☆1,809Apr 26, 2024Updated 2 years ago
- BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JS…☆41Mar 15, 2021Updated 5 years ago
- A tool for fetching archived URLs (to be rewritten in Go).☆41Jul 19, 2018Updated 8 years ago
- OWASP ZAP add-on to detect reflected parameter vulnerabilities efficiently☆12Feb 19, 2021Updated 5 years ago
- This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, …☆53Mar 29, 2023Updated 3 years ago
- A Burp Extension designed to identify argument injection vulnerabilities.☆124Apr 16, 2019Updated 7 years ago
- OSINT scanning tool which discovers and maps directories found in javascript files hosted on a website.☆227Feb 24, 2019Updated 7 years ago
- Hacked together script for feeding urls into Burp's Sitemap☆95Jul 30, 2026Updated 2 weeks ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Various Python scripts that have come in handy but aren't important enough to get their own repository☆22Feb 18, 2021Updated 5 years ago
- A simple SSRF-testing sheriff written in Go☆338Oct 31, 2024Updated last year
- JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing.☆100Jul 29, 2019Updated 7 years ago
- Dr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful information! It's yo…☆218Oct 31, 2019Updated 6 years ago
- XSS Hunter Burp Plugin☆152Aug 31, 2018Updated 7 years ago
- A bunch of tricks and configs to configure a work environment for web pentesting☆13Oct 1, 2018Updated 7 years ago
- Top level domain scanner in Go☆30Sep 24, 2023Updated 2 years ago
- Burp Suite extension to track vulnerability assessment progress☆59Mar 7, 2020Updated 6 years ago
- Burp Suite extension to easily export sub domains☆45Nov 29, 2019Updated 6 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A Burp Suite extension to add a custom header (e.g. JWT)☆19Dec 9, 2021Updated 4 years ago
- Match and Replace script used to automatically generate JSON option file to BurpSuite☆213May 13, 2019Updated 7 years ago
- Burp extension to increment a parameter in each active scan request☆13Aug 6, 2026Updated last week
- Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)☆463May 10, 2019Updated 7 years ago
- Boxer: A fast directory bruteforce tool written in Python with concurrency.☆14Feb 26, 2021Updated 5 years ago
- Keye is a reconnaissance tool that was written in Python with SQLite3 integrated. After adding a single URL, or a list of URLs, it will m…☆100Dec 30, 2019Updated 6 years ago
- This tool is for automate the initial things that we usually do in daily pentesting. So you can focus more on the main target.☆77Nov 10, 2019Updated 6 years ago