Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki
☆215Oct 31, 2024Updated last year
Alternatives and similar repositories for web-methodology
Users that are interested in web-methodology are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆46Sep 10, 2020Updated 5 years ago
- ☆24Jan 26, 2021Updated 5 years ago
- sub domain wild card filtering tool☆40Apr 18, 2020Updated 6 years ago
- Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"☆358Oct 14, 2020Updated 5 years ago
- differer finds how URLs are parsed by different languages in order to help bug hunters break filters☆63May 3, 2020Updated 6 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A command line tool that reads from stdin and strips ANSI color codes from the input.☆10Feb 11, 2023Updated 3 years ago
- Salesforce Policy Deviation Checker☆30Sep 30, 2020Updated 5 years ago
- Find cloud assets that no one wants exposed 🔎 ☁️☆353Jul 20, 2020Updated 6 years ago
- List HackerOne private program assets☆157Jun 24, 2021Updated 5 years ago
- Extract SSL certificate data (Subject Name, Subject Alt Names, Organisation)☆42Nov 10, 2025Updated 9 months ago
- A wrapper around jq, to help you parse jq output!☆30Aug 23, 2020Updated 6 years ago
- GraphQL automatic fuzzing tool☆16Jul 16, 2021Updated 5 years ago
- The Web Security Testing Guide is a comprehensive open source guide to testing the security of web applications and web services.☆32Oct 27, 2025Updated 10 months ago
- ☆130Jun 15, 2020Updated 6 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- A collection of scripts for bug-bounty related stuff☆38Sep 4, 2020Updated 5 years ago
- A golang utility to spider through a website searching for additional links.☆343Nov 7, 2020Updated 5 years ago
- A checklist of practices for organizations dealing with account takeover (ATO)☆273Oct 4, 2024Updated last year
- Clientside vulnerability / reflected xss fuzzer☆150Jul 29, 2023Updated 3 years ago
- This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes …☆260Oct 16, 2022Updated 3 years ago
- ☆29Sep 25, 2020Updated 5 years ago
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆159Nov 24, 2023Updated 2 years ago
- Client Side Prototype Pollution Scanner☆530Sep 17, 2022Updated 3 years ago
- Terraform configuration to build a Burp Private Collaborator Server☆28Sep 16, 2018Updated 7 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆703Nov 27, 2024Updated last year
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆649Jul 7, 2025Updated last year
- xss development frameworks, with the goal of making payload writing easier.☆160Aug 7, 2024Updated 2 years ago
- Dump all available paths and/or endpoints on WADL file.☆96Nov 24, 2025Updated 9 months ago
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3☆2,095Jan 2, 2024Updated 2 years ago
- ☆14Jul 13, 2020Updated 6 years ago
- Script for monitoring changes in javascript files on WebApps for offensive reconnaissance.☆29Aug 4, 2021Updated 5 years ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆300Feb 12, 2023Updated 3 years ago
- Visualize your Terraform files☆34Sep 9, 2020Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.☆1,452Feb 10, 2026Updated 6 months ago
- Tool to check for dependency confusion vulnerabilities in multiple package management systems☆790Aug 19, 2024Updated 2 years ago
- Benchmarking repo for secrets scanning☆250Aug 18, 2024Updated 2 years ago
- Secret and/or credential patterns used for gf.☆246Feb 10, 2023Updated 3 years ago
- Reverse proxies cheatsheet☆1,886Nov 4, 2023Updated 2 years ago
- Ffuf output browser☆38Feb 25, 2023Updated 3 years ago
- MetaSec.js combines all the free open-source security tools to identify issues with JavaScript and automates the boring parts☆83Feb 4, 2023Updated 3 years ago