silentsignal / SemGWT
Semgrep rules to identify GWT attack surface
☆11Updated 2 years ago
Alternatives and similar repositories for SemGWT:
Users that are interested in SemGWT are comparing it to the libraries listed below
- Supporting material for the "Hunting Bugs In The Tropics" DEFCON 30 talk☆9Updated 2 years ago
- Pythonize Intruder Payload☆13Updated 4 years ago
- LetMeOutOfYour.net Resources☆20Updated 4 years ago
- Take a list of URIs and print all the of the paths☆10Updated 4 years ago
- ☆18Updated last year
- Push notifications to Slack channel or to custom server based on BurpSuite response conditions.☆17Updated 4 years ago
- This extension replaces the default repeater tab name with the URL path of the repeater request.☆22Updated 3 years ago
- A parallel scanner that utilises axiom to spin up servers and parallel scan using masscan.☆16Updated 4 years ago
- This extension redacts potentially sensitive header and parameter values from requests using Shannon Entropy analysis.☆12Updated 4 years ago
- Example of a serverless web reconaissance workflow's AWS architecture.☆11Updated 2 years ago
- Atlassian Confluence CVE-2021-26084 one-liner mass checker☆30Updated 3 years ago
- parsers to make life easier☆13Updated 4 years ago
- ☆10Updated 6 years ago
- A Burp Extender plugin that will allow you to tamper with requests containing compressed, serialized java objects.☆24Updated 6 years ago
- Take a list of IP addresses and probe for working HTTP and HTTPS servers☆12Updated 5 years ago
- My python3 implementation of a Forward Shell☆35Updated 6 years ago
- A handy plugin for copying requests/responses directly from Burp, some extra magic included.☆13Updated 3 years ago
- ☆26Updated 2 years ago
- Signatures for wraith used to detect secrets across various sources☆15Updated 2 years ago
- View screenshots as a slideshow over http☆15Updated 5 years ago
- Burp extension to generate multi-step CSRF POC.☆30Updated 5 years ago
- A pair of scripts to import session and local group information that has been collected from alternate data sources into BloodHound's Neo…☆19Updated 2 years ago
- ☆12Updated 3 years ago
- A playground to practice SSRF Attacks against web apps☆17Updated 6 years ago
- A multi-threaded scanner that helps identify CORS flaws/misconfigurations☆19Updated 5 years ago
- Test Azure environment for MFA misconfigurations☆11Updated 2 years ago
- ☆16Updated 2 years ago
- A tools for JavaScript Recon☆21Updated 4 years ago
- Automated compromise detection of the world's most popular packages☆15Updated last year
- Extract subdomains from rapiddns.io☆23Updated 2 years ago