secdec / attack-surface-detector-cli
☆80Updated 3 years ago
Alternatives and similar repositories for attack-surface-detector-cli:
Users that are interested in attack-surface-detector-cli are comparing it to the libraries listed below
- A script for installing private Burp Collaborator with free Let's Encrypt SSL-certificate☆209Updated 10 months ago
- This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes …☆258Updated 2 years ago
- GoFingerprint is a Go tool for taking a list of target web servers and matching their HTTP responses against a user defined list of fing…☆205Updated last year
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆102Updated last year
- Searching for virtual hosts among non-resolvable domains☆88Updated 4 years ago
- The Burp extension to check JWT (JSON Web Tokens) for using keys from known from public sources☆130Updated 4 years ago
- Automatically modify the User-Agent header in all Burp requests☆56Updated 7 years ago
- Vulnerable SAML infrastructure training applicaiton☆51Updated 2 years ago
- A Burp Suite Extension for parsing Project Files from the CLI.☆87Updated 7 months ago
- ☆71Updated 4 years ago
- ☆148Updated 3 years ago
- Adds a customizable "Send to..."-context-menu to your BurpSuite.☆155Updated 2 years ago
- A natural evolution of Burp Suite's Repeater tool☆92Updated last year
- A script that can resolve an input file of domains and scan them with masscan☆157Updated 4 years ago
- ASN reconnaissance script☆127Updated last year
- Turbo Intruder Scripts☆221Updated 4 years ago
- Custom scripts for the PIPER Burp extensions.☆98Updated last year
- A tool geared towards pentesting APIs using OpenAPI definitions.☆174Updated 2 years ago
- A simple remote scanner for Atlassian Jira☆121Updated 2 years ago
- Tools to assess the DNS security of web applications☆128Updated 2 years ago
- Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in …☆200Updated last year
- NotSoCereal: A Deserialization exploit playground☆52Updated 3 years ago
- A Tool for Domain Flyovers☆104Updated 5 months ago
- Various Payload wordlists☆235Updated 4 years ago
- Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops☆42Updated last year
- XSS Payload without Anything.☆106Updated 5 years ago
- Weaponizing Live CT logs for automated monitoring of assets☆133Updated 3 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures t…☆211Updated 5 years ago
- A list of "secrets" from JWT sample code and readme files.☆55Updated 4 years ago