owasp-amass / open-asset-model
Asset definitions for an organization's external attack surface
☆44Updated last week
Related projects ⓘ
Alternatives and complementary repositories for open-asset-model
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆30Updated last year
- Database interaction layer to store open-asset-models in sqlite3 and postgres☆16Updated this week
- Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.☆29Updated 2 years ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆51Updated 2 months ago
- Additional active scan checks for BURP☆20Updated last month
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated 3 months ago
- 🔗 A curated list of awesome Caido related projects☆34Updated last month
- An Evil OIDC Server☆51Updated 2 years ago
- Backend for Nuclear Pond☆21Updated 11 months ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆45Updated 2 months ago
- Fast and lightweight Web Application Firewall Fingerprinting tool☆61Updated last year
- A blazing-fast, thread-safe, straightforward and zero memory allocations tool to swiftly generate alternative IP(v4) address representati…☆85Updated last year
- A companion repo to accompany detailed guides and YouTube content to allow users to follow along☆12Updated 4 years ago
- AssetViz simplifies the visualization of subdomains from input files, presenting them as a coherent mind map. Ideal for penetration test…☆30Updated 7 months ago
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- Jumpstart multiple WebSocket servers quickly☆28Updated 2 years ago
- Ffuf output browser☆37Updated last year
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities☆25Updated 4 months ago
- ☆27Updated last year
- FastCVE - fast, rich and API-based search for CVE and more (CPE, CWE, CAPEC)☆39Updated 3 months ago
- security.txt collection of most popular world-wide domains☆52Updated last year
- DNS resolution tracing tool☆34Updated 3 years ago
- A collection of one off hacks and simple scripts☆27Updated last year
- ☆11Updated last year
- A tool to parse, deduplicate, and query multiple port scans.☆57Updated last year
- Basic implementation of certstream to print new subdomains and domains☆37Updated 3 years ago
- A BurpSuite plugin for BBRF☆24Updated this week
- Take domains on stdin and output them on stdout if they get resolved☆33Updated 2 years ago
- Signatures for wraith used to detect secrets across various sources☆15Updated 2 years ago