synack / wstg
The Web Security Testing Guide is a comprehensive open source guide to testing the security of web applications and web services.
☆28Updated 2 years ago
Alternatives and similar repositories for wstg:
Users that are interested in wstg are comparing it to the libraries listed below
- The project aims at creating target-specific wordlists for any web application that you are testing.☆64Updated 2 years ago
- ☆65Updated 2 years ago
- Archived Please go to https://github.com/adamjsturge/xsshunter-go☆31Updated 11 months ago
- Get all the CNs from a list of domains☆46Updated 3 years ago
- ☆61Updated 6 months ago
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆66Updated 4 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆130Updated 3 years ago
- Horizontal Domain Discovery☆75Updated last year
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- Find subdomains and takeovers.☆84Updated 2 years ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆80Updated 2 years ago
- ☆37Updated 2 weeks ago
- Misc bounty and vulndisc things☆83Updated 4 years ago
- Script to test open Akamai ARL vulnerability.☆70Updated 3 years ago
- ☆74Updated 9 months ago
- Tool for making it easy to collect dns results from the CLI☆39Updated 6 months ago
- ☆76Updated 4 years ago
- 3klector is an automation Recon tool which collecting information about Acquisitions and ASN which related to Big Scope company☆49Updated 2 years ago
- A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks☆57Updated 5 years ago
- Custom scripts for the PIPER Burp extensions.☆97Updated last year
- Vulnerable SAML infrastructure training applicaiton☆50Updated 2 years ago
- Prototype Pollution Scanner☆109Updated 3 years ago
- ☆59Updated 7 months ago
- ☆20Updated 2 years ago
- A Python Library designed to facilitate interaction with Synack's undocumented API endpoints☆24Updated last week
- golang tool to scan domains or single domains with know security issues against xmlrpc☆60Updated last year
- Burp-suite Extension For finding .map files☆44Updated last year
- It grep subdomains, email/username, build custom wordlist etc from gau results☆47Updated 2 years ago
- ☆94Updated 3 years ago
- A quick ‘n dirty nmap parser written in Golang to convert nmap xml to IP:Port notation.☆125Updated 7 months ago