PortSwigger's Repositories

100 repositories

3d-css-tutorial
No description
โญ 14 ๐ŸŒ Public
403-bypasser
No description
โญ 71 ๐ŸŒ Public
429-bypasser
No description
โญ 4 ๐ŸŒ Public
5gc-api-parse
A BurpSuite extension to parse 5GC NF OpenAPI 3.0 files to assess 5G core networks
โญ 7 ๐ŸŒ Public
acmate
ACMate - a tool for Reverse-engineering and Testing of Access Control Policies of Web Applications
โญ 0 ๐ŸŒ Public
activation-script
Activate Burp from a script
โญ 0 ๐ŸŒ Public
active-scan-plus-plus
ActiveScan++ Burp Suite Plugin
โญ 240 ๐ŸŒ Public
add-custom-header
A Burp Suite extension to add a custom header (e.g. JWT)
โญ 19 ๐ŸŒ Public
add-to-sitemap-plus
No description
โญ 4 ๐ŸŒ Public
add-to-tls-pass-through
Burp Extension to add context menus for configuration of the Add to TLS Pass Through setting
โญ 6 ๐ŸŒ Public
add-track-custom-issues
No description
โญ 1 ๐ŸŒ Public
additional-cors-checks
No description
โญ 11 ๐ŸŒ Public
additional-csrf-checks
No description
โญ 7 ๐ŸŒ Public
additional-scanner-checks
Collection of scanner checks missing in Burp
โญ 31 ๐ŸŒ Public
adhoc-payload-processors
Generate payload processors on the fly - without having to create individual extensions.
โญ 6 ๐ŸŒ Public
admin-panel-finder
A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)
โญ 1 ๐ŸŒ Public
aes-killer
Burp Plugin to decrypt AES encrypted traffic on the fly
โญ 18 ๐ŸŒ Public
aes-payloads
Burp Extension to manipulate AES encrypted payloads
โญ 13 ๐ŸŒ Public
agartha
a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to spot authentication/authorization issues, and converts Http requests to Javascript for further XSS exploitation.
โญ 28 ๐ŸŒ Public
ai-http-analyzer
AIHTTPAnalyzer revolutionizes web application security testing by bringing artificial intelligence capabilities to Burp Suite. This innovative extension harnesses the power of AI to automate vulnerability detection, provide intelligent analysis, and assist security professionals in identifying complex security issues.
โญ 26 ๐ŸŒ Public
ai-prompt-fuzzer
Burp extension to fuzz/brute force GenAI/LLM prompts using a list of various payloads.
โญ 17 ๐ŸŒ Public
ai-recon-assistant
No description
โญ 2 ๐ŸŒ Public
ai-substitutor
AI Substitutor is an extension for Burp Suite that uses AI functionality to substitute values of HTTP request parameters and headers.
โญ 0 ๐ŸŒ Public
amf-deserializer
A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library
โญ 9 ๐ŸŒ Public
anonymous-cloud
Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities
โญ 14 ๐ŸŒ Public
anti-csrf-token-from-referer
No description
โญ 2 ๐ŸŒ Public
api-exporter
No description
โญ 1 ๐ŸŒ Public
api-sword
NSFOCUS API_Sword๏ผšA Burp Suite extension, Automatically recursively collect API endpoints from any response
โญ 0 ๐ŸŒ Public
assertj-swing
Fluent assertions for Swing apps
โญ 1 ๐ŸŒ Public
asset-discovery
Burp Suite extension to discover assets from HTTP response.
โญ 16 ๐ŸŒ Public
asset-saver
Burp Suite extension for saving previously loaded assets
โญ 0 ๐ŸŒ Public
ator
No description
โญ 32 ๐ŸŒ Public
attack-selector
Burp Suite Attack Selector Plugin
โญ 11 ๐ŸŒ Public
attack-surface-detector
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
โญ 14 ๐ŸŒ Public
auth-analyzer
No description
โญ 109 ๐ŸŒ Public
auth-matrix
AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.
โญ 43 ๐ŸŒ Public
authz
No description
โญ 108 ๐ŸŒ Public
auto-gql
A plugin for Burp Suite Pro that uses the GraphQL schema to begin Active Scanning the entire endpoint.
โญ 3 ๐ŸŒ Public
auto-repeater
Automated HTTP Request Repeating With Burp Suite
โญ 69 ๐ŸŒ Public
autocompletion
This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.
โญ 1 ๐ŸŒ Public
autorize
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
โญ 265 ๐ŸŒ Public
autovader
An extension to automate using DOM Invader from within Burp
โญ 6 ๐ŸŒ Public
autowasp
BurpSuite Extension: A one-stop pen testing checklist and logger tool
โญ 267 ๐ŸŒ Public
aws-cognito
No description
โญ 3 ๐ŸŒ Public
aws-curl-command
Burp Extension to create AWS Curl and cURL with SigV4 commands from an API
โญ 2 ๐ŸŒ Public
aws-security-checks
AWS Security Checks
โญ 40 ๐ŸŒ Public
aws-signer
Burp Extension for AWS Signing
โญ 6 ๐ŸŒ Public
aws-sigv4
Anvil Ventures' Burp extension for signing AWS requests with SigV4
โญ 3 ๐ŸŒ Public
awscurl-burp-extension-main
Burp Extension to create AWS Curl and cURL with SigV4 commands from an API
โญ 0 ๐ŸŒ Public
awscurl-burp-extension-test-3
Burp Extension to create AWS Curl and cURL with SigV4 commands from an API
โญ 0 ๐ŸŒ Public
backslash-powered-scanner
Finds unknown classes of injection vulnerabilities
โญ 707 ๐ŸŒ Public
backup-finder
A burp suite extension that reviews backup, old, temporary and unreferenced files on web server for sensitive information (OWASP OTG-CONFIG-004)
โญ 11 ๐ŸŒ Public
bad-character-wordlist-generator
Burp Suite extension that Generator Wordlist with encoding options and prefix/suffix for generating payloads and FUZZing
โญ 0 ๐ŸŒ Public
bambdas
Bambdas collection for Burp Suite Professional and Community.
โญ 451 ๐ŸŒ Public
batch-scan-report-generator
Small Burp Suite Extension to generate multiple scan reports by host with just a few clicks. Works with Burp Suite Professional only.
โญ 4 ๐ŸŒ Public
BChecks
BChecks collection for Burp Suite Professional and Burp Suite DAST
โญ 753 ๐ŸŒ Public
beanstack-stacktrace-fingerprinter
X41 BeanStack - Stack Trace Fingerprinting BETA
โญ 5 ๐ŸŒ Public
blazer
Burp Suite AMF Extension
โญ 1 ๐ŸŒ Public
blazor-traffic-processor
No description
โญ 3 ๐ŸŒ Public
blind-xss-injector
Burp Suite plugin to test for blind XSS vulnerabilities
โญ 0 ๐ŸŒ Public
bookmarks
A Burp Suite Extension to take back your repeater tabs
โญ 3 ๐ŸŒ Public
bradamsa
Burp Suite extension to generate Intruder payloads using Radamsa
โญ 0 ๐ŸŒ Public
brida
The new bridge between Burp Suite and Frida!
โญ 27 ๐ŸŒ Public
broken-link-hijacking
Broken Link Hijacking Burp Extension
โญ 7 ๐ŸŒ Public
browser-repeater
BurpSuite extension for Repeater tool that renders responses in a real browser.
โญ 9 ๐ŸŒ Public
bseept
Burp Suite DAST Power Tools
โญ 22 ๐ŸŒ Public
buby
A JRuby implementation of the BurpExtender interface for PortSwigger Burp Suite.
โญ 2 ๐ŸŒ Public
bugpoc
Burp Suite Extension to send raw HTTP Requests to BugPoC.com
โญ 2 ๐ŸŒ Public
bulk-send-to-repeater
bulkAddToRepeater Burp Extension to Allow Mass "Send to Repeater" Using Context Menu
โญ 0 ๐ŸŒ Public
burp-2-slack
Push notifications to Slack channel or to custom server based on BurpSuite response conditions.
โญ 10 ๐ŸŒ Public
burp-2-telegram
Push notifications to Telegram bot on BurpSuite response conditions.
โญ 10 ๐ŸŒ Public
burp-auto-drop
Burp extension to automatically drop requests that match a certain regex.
โญ 2 ๐ŸŒ Public
burp-beautifier
Burpsuite extension for beautifying writing in Jython
โญ 3 ๐ŸŒ Public
burp-chat
burpChat is a BurpSuite plugin that enables collaborative BurpSuite usage using XMPP/Jabber.
โญ 0 ๐ŸŒ Public
burp-csj
BurpCSJ extension for Burp Pro - Crawljax Selenium JUnit integration
โญ 0 ๐ŸŒ Public
burp-extender-api
Burp Wiener API (Legacy)
โญ 62 ๐ŸŒ Public
burp-extensions-montoya-api
Burp Extensions Api
โญ 182 ๐ŸŒ Public
burp-extensions-montoya-api-examples
Examples for using the Montoya API with Burp Suite
โญ 167 ๐ŸŒ Public
burp-hash
No description
โญ 1 ๐ŸŒ Public
burp-jenkins-integration
DAST integration with Jenkins
โญ 1 ๐ŸŒ Public ๐Ÿ“ฆ Archived
burp-share-requests
This Burp Suite extension enables the generation of shareable links to specific requests which other Burp Suite users can import.
โญ 9 ๐ŸŒ Public
burp-smart-buster
A Burp Suite content discovery plugin that add the smart into the Buster!
โญ 32 ๐ŸŒ Public
burp-subdomain
Burp Suite extension to easily export sub domains
โญ 12 ๐ŸŒ Public
burp-suite-enterprise-edition-ami
No description
โญ 6 ๐ŸŒ Public
burp-to-discord
No description
โญ 1 ๐ŸŒ Public
burp-variables
Burp Suite extension that extends Burp to support storing and reusing variables in requests
โญ 5 ๐ŸŒ Public
burpcrypto
BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). ๆ”ฏๆŒๅคš็งๅŠ ๅฏ†็ฎ—ๆณ•ๆˆ–็›ดๆŽฅๆ‰ง่กŒJSไปฃ็ ็š„็”จไบŽ็ˆ†็ ดๅ‰็ซฏๅŠ ๅฏ†็š„BurpSuiteๆ’ไปถ
โญ 6 ๐ŸŒ Public
burpelfish
BurpelFish - Adds Google Translate to Burp's Context Menu. "Babel Fish" language translation for app-sec testing in other languages.
โญ 11 ๐ŸŒ Public
burpkit
Next-gen BurpSuite penetration testing tool
โญ 5 ๐ŸŒ Public
burptrast
Burp Plugin for Contrast Security
โญ 0 ๐ŸŒ Public
bypass-bot-detection
Burp Suite extension that mutates ciphers to bypass TLS-fingerprint based bot detection
โญ 443 ๐ŸŒ Public
bypass-suite
BurpSuite extensions -Bypass Suite
โญ 3 ๐ŸŒ Public
bypass-waf
Add headers to all Burp requests to bypass some WAF products
โญ 43 ๐ŸŒ Public
c-surfer
A CSRF guard hiding extension that keeps track of the latest guard value per session and update new requests accordingly
โญ 2 ๐ŸŒ Public
cache-killer
No description
โญ 24 ๐ŸŒ Public
captcha-converter
A Burp Suite extension for converting Base64 data to an image.
โญ 1 ๐ŸŒ Public
carbonator
Integris Security Carbonator - The Burp Suite Pro extension that automates scope, spider & scan from the command line. Carbonator helps automate the vulnerability scanning of web applications. Either 1 or 100 web applications can be scanned by issuing a single command. Carbonator is now available from within Burp Suite Pro through the BApp Store.
โญ 2 ๐ŸŒ Public
certsquirt
A golang PKI in less than 1000 lines of code.
โญ 8 ๐ŸŒ Public
change-menu-level
ไธ€ไธช็”จไบŽไฟฎๆ”นๅณ้”ฎๆ’ไปถ่œๅ•ๅฑ‚็บง็š„Burpsuiteๆ’ไปถใ€‚A simple BurpSuite extension to change extension context menu level.
โญ 14 ๐ŸŒ Public
ci-cd-platform-scanning-examples
No description
โญ 4 ๐ŸŒ Public