synack / wstg
The Web Security Testing Guide is a comprehensive open source guide to testing the security of web applications and web services.
☆28Updated 2 years ago
Alternatives and similar repositories for wstg:
Users that are interested in wstg are comparing it to the libraries listed below
- ☆66Updated 2 years ago
- ☆61Updated 7 months ago
- ☆55Updated 10 months ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆130Updated 4 years ago
- The project aims at creating target-specific wordlists for any web application that you are testing.☆64Updated 2 years ago
- Horizontal Domain Discovery☆75Updated last year
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- Misc bounty and vulndisc things☆84Updated 4 years ago
- Vulnerable SAML infrastructure training applicaiton☆50Updated 2 years ago
- Archived Please go to https://github.com/adamjsturge/xsshunter-go☆31Updated last year
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆66Updated 4 years ago
- Tool for making it easy to collect dns results from the CLI☆40Updated 7 months ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- Find subdomains and takeovers.☆84Updated 2 years ago
- AWS S3 open bucket poc automated script.☆57Updated 3 years ago
- 3klector is an automation Recon tool which collecting information about Acquisitions and ASN which related to Big Scope company☆48Updated 2 years ago
- A burpsuite extension that helps security researchers find public security reports published on h1 based on the selected host☆42Updated 4 years ago
- Intentionally Vulnerable Nodejs Application & APIs☆22Updated 2 years ago
- A Python Library designed to facilitate interaction with Synack's undocumented API endpoints☆24Updated last week
- golang tool to scan domains or single domains with know security issues against xmlrpc☆62Updated last year
- ☆59Updated 8 months ago
- Go fish for AWS EIPs☆46Updated 3 years ago
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- A docker image which will enumerate, sort, unique and resolve the results of various subdomains enumeration tools.☆70Updated 7 months ago
- Notes for CRTP☆40Updated 4 years ago
- Prototype Pollution Scanner☆113Updated 3 years ago
- This repository is intended for sharing files/tools/tutorials..etc that related to eWPTXv1 from eLearnSecurity☆23Updated 4 years ago
- ☆95Updated 3 years ago
- Sometimes we want to fuzz a set of sub-domain URLs with a common wordlist. Fuzzing them one by one is a tedious task, not to mention the …☆51Updated 3 years ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆80Updated 2 years ago