TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite
☆97Aug 24, 2026Updated last month
Alternatives and similar repositories for TokenTwin-Checker
Users that are interested in TokenTwin-Checker are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An advanced Out-of-Band and In-Band SSRF fuzzing scanner with dynamic request tracking.☆40Jun 18, 2026Updated 3 months ago
- Stealth hybrid URL mapper☆31May 1, 2026Updated 5 months ago
- My Main App Hacking CheckList☆35Jun 20, 2026Updated 3 months ago
- A practical security workbook for reviewing source code, identifying vulnerabilities, validating findings with test cases, and automating…☆30Sep 4, 2026Updated 3 weeks ago
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods☆27Jul 15, 2026Updated 2 months ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ☆50Feb 27, 2026Updated 7 months ago
- SSRFHunter☆18Jan 17, 2026Updated 8 months ago
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆61Jul 12, 2026Updated 2 months ago
- Apkx-Hunter is an Android Static Analysis Framework in Debian Package written entirely in C with OWASP MASVS scanning with 15 categories …☆94Sep 15, 2026Updated 2 weeks ago
- Open-source passive reconnaissance and exposure discovery tool that leverages VirusTotal and the Wayback Machine to uncover subdomains, U…☆145Sep 20, 2026Updated last week
- An obsessive, expert-tier knowledge base + AI skill system for professional bug bounty hunting, security research, and penetration testin…☆54Apr 25, 2026Updated 5 months ago
- Active Directory forensic framework☆16May 18, 2026Updated 4 months ago
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆34May 28, 2026Updated 4 months ago
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆29Jun 16, 2026Updated 3 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Bug Bounty Methodology☆337Aug 4, 2026Updated last month
- AI-Powered Agents for Bub-Bounty Pentesting and Red-Teaming purposes☆434Apr 30, 2026Updated 5 months ago
- Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) i…☆63Jul 22, 2026Updated 2 months ago
- GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumera…☆44Aug 9, 2026Updated last month
- A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug…☆19May 20, 2026Updated 4 months ago
- Autonomous AI pentesting daemon — 34 security tools, 15 vuln classes, WAF bypass engine, LLM analysis. Free tier models (<$3/mo). HackerO…☆81Aug 7, 2026Updated last month
- POCs to demonstrate CVE-2026-42167 in ProFTPD☆24Apr 29, 2026Updated 5 months ago
- ☆99May 11, 2026Updated 4 months ago
- AI-powered modular Active Directory red-team framework for authorized penetration testing, AD enumeration, attack-path analysis, Kerber…☆357Jun 11, 2026Updated 3 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Live runtime audit for installed Android apps. Runs on the rooted phone, serves a browser dashboard.☆33May 23, 2026Updated 4 months ago
- ♥☆222Sep 7, 2025Updated last year
- Fully local vulnerability research pipeline - 14B code-specialized LLM reviews every source file exhaustively.☆170Sep 5, 2026Updated 3 weeks ago
- This lab is for **EDUCATIONAL PURPOSES ONLY**. Use it responsibly and only on systems you own or have explicit permission to test. Do not…☆24Feb 20, 2026Updated 7 months ago
- Auto Frida is a powerful, all-in-one automation toolkit that handles everything from Frida installation to script injection. Zero manual …☆136Apr 15, 2026Updated 5 months ago
- ☆79May 5, 2025Updated last year
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆24Mar 16, 2026Updated 6 months ago
- It serves as a practical guide for security researchers to identify and test WordPress targets effectively during bug bounty hunting.☆27Jul 19, 2026Updated 2 months ago
- ☆105Sep 18, 2026Updated 2 weeks ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆93Feb 13, 2026Updated 7 months ago
- Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier☆244Sep 11, 2026Updated 3 weeks ago
- Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian☆329Sep 1, 2026Updated last month
- Kali Linux Polyglot Framework for Autonomous Pentesting/Cyber Security☆137Aug 16, 2026Updated last month
- AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)☆462Jul 4, 2026Updated 2 months ago
- ☆203Jan 22, 2026Updated 8 months ago
- RepShot · Generate professional security finding cards directly from Burp Suite Repeater.☆109May 31, 2026Updated 4 months ago