synack / wstg
The Web Security Testing Guide is a comprehensive open source guide to testing the security of web applications and web services.
☆29Updated 2 years ago
Alternatives and similar repositories for wstg:
Users that are interested in wstg are comparing it to the libraries listed below
- ☆65Updated 2 years ago
- The project aims at creating target-specific wordlists for any web application that you are testing.☆65Updated 2 years ago
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- A quick ‘n dirty nmap parser written in Golang to convert nmap xml to IP:Port notation.☆127Updated 9 months ago
- ☆56Updated 11 months ago
- Archived Please go to https://github.com/adamjsturge/xsshunter-go☆31Updated last year
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆131Updated 4 years ago
- Misc bounty and vulndisc things☆84Updated 4 years ago
- s3 brute force tool☆44Updated 3 years ago
- Vulnerable SAML infrastructure training applicaiton☆51Updated 2 years ago
- Horizontal Domain Discovery☆76Updated last year
- ☆37Updated 2 months ago
- Find subdomains and takeovers.☆84Updated 2 years ago
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆66Updated 4 years ago
- A Python Library designed to facilitate interaction with Synack's undocumented API endpoints☆24Updated last month
- IIS shortname scanner + bruteforce☆52Updated last year
- Searching for virtual hosts among non-resolvable domains☆87Updated 4 years ago
- A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks☆58Updated 5 years ago
- A list of "secrets" from JWT sample code and readme files.☆54Updated 4 years ago
- Get all the CNs from a list of domains☆46Updated 3 years ago
- 3klector is an automation Recon tool which collecting information about Acquisitions and ASN which related to Big Scope company☆48Updated 2 years ago
- Collection grep patterns for Tomnomnom tools namely gf☆44Updated last week
- Golang tool which helps dropping the irrelevant entries from your ffuf result file.☆134Updated 6 months ago
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆68Updated 4 years ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆80Updated 2 years ago
- A burpsuite extension that helps security researchers find public security reports published on h1 based on the selected host☆42Updated 4 years ago
- A Burp Suite Extension for parsing Project Files from the CLI.☆87Updated 6 months ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- ☆61Updated 8 months ago
- Python Duo Push API☆35Updated 3 weeks ago