synack / wstg
The Web Security Testing Guide is a comprehensive open source guide to testing the security of web applications and web services.
☆29Updated 2 years ago
Alternatives and similar repositories for wstg:
Users that are interested in wstg are comparing it to the libraries listed below
- ☆65Updated 2 years ago
- The project aims at creating target-specific wordlists for any web application that you are testing.☆66Updated 2 years ago
- Archived Please go to https://github.com/adamjsturge/xsshunter-go☆31Updated last year
- 3klector is an automation Recon tool which collecting information about Acquisitions and ASN which related to Big Scope company☆48Updated 2 years ago
- Extract JavaScript files from burp suite project with ease.☆89Updated 3 years ago
- A Python Library designed to facilitate interaction with Synack's undocumented API endpoints☆24Updated 2 months ago
- Horizontal Domain Discovery☆76Updated last year
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- ☆56Updated 11 months ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- s3 brute force tool☆44Updated 3 years ago
- golang tool to scan domains or single domains with know security issues against xmlrpc☆62Updated last year
- Vulnerable SAML infrastructure training applicaiton☆53Updated 2 years ago
- Awesome cloud enumerator☆40Updated 4 years ago
- HTTP parameter discovery suite.☆63Updated 4 years ago
- A quick ‘n dirty nmap parser written in Golang to convert nmap xml to IP:Port notation.☆127Updated 10 months ago
- Get the scope of your bugcrowd programs☆67Updated 4 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- ☆61Updated 9 months ago
- Burp-suite Extension For finding .map files☆46Updated last year
- A tool to guess the rest of the shortnames provided by vulnerable IIS instances.☆40Updated last year
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆65Updated 4 years ago
- A blazing fast & feature rich Amazon S3 bucket enumerator.☆96Updated 2 years ago
- A collection of useful grep patterns and tools by Tomnomnom for extracting specific values from text.☆45Updated last month
- ☆95Updated 3 years ago
- IIS shortname scanner + bruteforce☆52Updated last year
- Find subdomains and takeovers.☆84Updated 2 years ago
- A burpsuite extension that helps security researchers find public security reports published on h1 based on the selected host☆42Updated 4 years ago
- ☆17Updated 3 years ago
- ☆37Updated 3 months ago