szski / shapeshifter
GraphQL security testing tool
☆120Updated 2 years ago
Alternatives and similar repositories for shapeshifter:
Users that are interested in shapeshifter are comparing it to the libraries listed below
- Continuous monitoring for JavaScript files☆219Updated 5 years ago
- MetaSec.js combines all the free open-source security tools to identify issues with JavaScript and automates the boring parts☆80Updated last year
- Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures t…☆205Updated 4 years ago
- Bass grabs you those "extra resolvers" you are missing out on when performing Active DNS enumeration. Add anywhere from 100-6k resolvers …☆141Updated 9 months ago
- ☆149Updated last year
- A tool geared towards pentesting APIs using OpenAPI definitions.☆172Updated 2 years ago
- GoFingerprint is a Go tool for taking a list of target web servers and matching their HTTP responses against a user defined list of fing…☆201Updated last year
- A permutation generation tool written in golang☆209Updated 5 years ago
- a .js scanner, built in php. designed to scrape urls and other info☆212Updated 7 years ago
- ASN reconnaissance script☆124Updated last year
- Burp Suite Extension to monitor new scope☆197Updated 3 years ago
- You can read the writeup on this script here☆191Updated 3 years ago
- ☆108Updated 4 years ago
- A simple SSRF-testing sheriff written in Go☆322Updated 2 months ago
- Suite of programs meant to aid in bug hunting and security assessments☆77Updated 5 years ago
- Takeover AWS ips and have a working POC for Subdomain Takeover.☆90Updated 10 months ago
- Quickly generate context-specific wordlists for content discovery from lists of URLs or paths☆216Updated 2 years ago
- The Burp extension to check JWT (JSON Web Tokens) for using keys from known from public sources☆128Updated 4 years ago
- Push notifications for passive DNS data☆107Updated 8 years ago
- Various Payload wordlists☆235Updated 4 years ago
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆188Updated 5 months ago
- SSRF testing tool☆243Updated 2 years ago
- Cross Origin Resource Sharing MisConfiguration Scanner☆171Updated 3 years ago
- A simple way of sending messages from the CLI output to your Slack with webhook.☆116Updated last year
- Predict Mongo ObjectIds☆127Updated 6 years ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆297Updated last year
- A script for installing private Burp Collaborator with free Let's Encrypt SSL-certificate☆205Updated 7 months ago
- ☆65Updated 2 years ago
- A natural evolution of Burp Suite's Repeater tool☆92Updated last year
- List HackerOne private program assets☆150Updated 3 years ago