Open Source Vulnerability Management Platform
-
Updated
Aug 28, 2025 - Python
Open Source Vulnerability Management Platform
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomains and more!
Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.
myscan 被动扫描
Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application Security Testing (DAST).
🧿 AutorizePro是一款强大越权检测 Burp 插件,通过增加 AI 辅助分析 && 进一步优化检测逻辑,大幅降低误报率,提升越权漏洞检出效率。 [ AutorizePro is a authorization enforcement detection extension for burp suite. By adding Ai-assisted analysis, it significantly reduces the false positive rate and improves the efficiency of vulnerability detection.
Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles
A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.
A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues
Roadmap for Web Application Penetration Testing | FREE Resources (Not Pirated)
Writeups for PortSwigger WebSecurity Academy
A Burp Suite Extension to extract interesting strings (key, secret, token, or etc.) from a webpage.
Burp extension to detect alias traversal via NGINX misconfiguration at scale.
Burp Automator - A Burp Suite Automation Tool. It provides a high level CLI and Python interfaces to Burp Suite scanner and can be used to setup Dynamic Application Security Testing (DAST).
burpsuite extension for check unauthorized vulnerability
gRPC-Web Pentesting Suite + Burp Suite Extension / Hack gRPC-Web Applications
Wordlist for content(directory) bruteforce discovering with Burp or dirsearch
Add a description, image, and links to the burpsuite topic page so that developers can more easily learn about it.
To associate your repository with the burpsuite topic, visit your repo's landing page and select "manage topics."