trickest / log4j
Trickest Workflow for discovering log4j vulnerabilities and gathering the newest community payloads.
ā110Updated 3 years ago
Alternatives and similar repositories for log4j:
Users that are interested in log4j are comparing it to the libraries listed below
- Check AWS S3 instances for read/write/delete accessā120Updated 3 years ago
- goverview - Get an overview of the list of URLsā143Updated last year
- š Collection of regexp pattern for security passive scanningā115Updated 2 years ago
- The project aims at creating target-specific wordlists for any web application that you are testing.ā65Updated 2 years ago
- A replacement of "qsreplace", accepts URLs as standard input, replaces all query string values with user-supplied values and stdout.ā105Updated 3 years ago
- A quick ān dirty nmap parser written in Golang to convert nmap xml to IP:Port notation.ā127Updated 9 months ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.ā71Updated 3 years ago
- nuclei-bb-templatesā49Updated 2 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or Lā¦ā132Updated 4 years ago
- ā44Updated 3 years ago
- A tool to perform permutations, mutations and alteration of subdomains in golang.ā159Updated last year
- ā87Updated 3 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.ā119Updated last year
- Improve automated and semi-automated active scanning in Burp Proā61Updated 2 years ago
- ā95Updated 3 years ago
- Community Workflow for the Osmedeus Engine that describes basic reconnaissance methodology for you to build your ownā71Updated last year
- Detects request smuggling via HTTP/2 downgrades.ā92Updated 2 years ago
- ā94Updated 3 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.ā164Updated 4 years ago
- Identify virtual hosts by similarity comparisonā119Updated 8 months ago
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environmentā44Updated 10 months ago
- Striping CDN IPs from a list of IP Addressesā76Updated 2 years ago
- Feed it a list of subdomains, it will resolve them and tell you which ones are internalā91Updated 3 years ago
- Burp Extension that copies a request and builds a FFUF skeletonā111Updated last year
- A Burp Suite Extension for parsing Project Files from the CLI.ā87Updated 6 months ago
- A projectdiscovery driven attack surface monitoring bot powered by axiomā182Updated 2 years ago
- List all public repositories for (valid) GitHub usernamesā73Updated last year
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizationsā58Updated last week
- Community curated list of template files for the nuclei engine to find security vulnerability and fingerprinting the targets.ā62Updated last year
- Find subdomains and takeovers.ā84Updated 2 years ago