mandatoryprogrammer / tarnish
A Chrome extension static analysis tool to help aide in security reviews.
☆150Updated last year
Alternatives and similar repositories for tarnish:
Users that are interested in tarnish are comparing it to the libraries listed below
- ReconJSON is a project dedicated to creating a flexible and consistent JSON format across popular recon tools.☆102Updated 5 years ago
- Application and Service Fingerprinting☆131Updated 2 years ago
- Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website☆138Updated 4 years ago
- Simple "postMessage logger" Chrome extension☆94Updated 4 years ago
- Files for appsecwiki.com☆115Updated 4 years ago
- Asynchronous wordlist based DKIM scanner☆58Updated 3 years ago
- This repository includes a set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard cer…☆281Updated this week
- Chrome extension to aid in finding DOMXSS by simple taint analysis of string values.☆81Updated 5 years ago
- HTML5 WebSocket message fuzzer☆144Updated 6 years ago
- ☆70Updated 7 years ago
- The DetectDynamicJS Burp Extension provides an additional passive scanner that tries to find differing content in JavaScript files and ai…☆65Updated 4 years ago
- Burp Suite extension to passively scan for applications revealing server error messages☆66Updated last year
- DupeKeyInjector☆135Updated 2 years ago
- [A]ndroid [A]pplication [P]entest [G]uide☆124Updated 5 years ago
- Actarus is a custom tool for bug bounty☆76Updated 5 years ago
- Automate common Chrome Debug Protocol tasks to help debug web applications from the command-line and actively monitor and intercept HTTP …☆73Updated 3 years ago
- Burp extension to detect alias traversal via NGINX misconfiguration at scale.☆255Updated 3 years ago
- The Outlook HTML Leak Test Project☆41Updated 6 years ago
- Pillage a git repo found in an accessible web root☆60Updated 13 years ago
- Burp Suite Extension to monitor new scope☆197Updated 3 years ago
- Tools to gather subdomains from Bug Bounty programs☆64Updated 6 years ago
- JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing.☆98Updated 5 years ago
- Proof-of-concept CORS exploitation tool.☆34Updated 5 years ago
- Simple trick to increase readability of exceptions raised by Burp extensions written in Python☆43Updated 7 years ago
- A repository for GraphQL Extension for Burp Suite☆58Updated 6 years ago
- A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.☆110Updated 5 years ago
- ☆36Updated 6 years ago
- Send notifications if a new program is published on HackerOne using Pushbullet☆26Updated 7 years ago
- XSS Hunter Burp Plugin☆149Updated 6 years ago
- Curated list of public penetration testing reports released by several consulting firms☆47Updated 6 years ago