{"id":43528302,"url":"https://github.com/jsmonhq/jsmon-burpsuite-extension","last_synced_at":"2026-02-03T15:17:40.889Z","repository":{"id":328818425,"uuid":"1116167461","full_name":"jsmonhq/jsmon-burpsuite-extension","owner":"jsmonhq","description":"Burpsuite Extension for Jsmon","archived":false,"fork":false,"pushed_at":"2025-12-15T14:14:29.000Z","size":137,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-12-18T18:20:12.694Z","etag":null,"topics":["burpsuite","extension","jsmon"],"latest_commit_sha":null,"homepage":"https://jsmon.sh","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jsmonhq.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-12-14T10:37:49.000Z","updated_at":"2025-12-18T06:41:05.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/jsmonhq/jsmon-burpsuite-extension","commit_stats":null,"previous_names":["jsmonhq/jsmon-burpsuite-extension"],"tags_count":2,"template":false,"template_full_name":null,"purl":"pkg:github/jsmonhq/jsmon-burpsuite-extension","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsmonhq%2Fjsmon-burpsuite-extension","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsmonhq%2Fjsmon-burpsuite-extension/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsmonhq%2Fjsmon-burpsuite-extension/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsmonhq%2Fjsmon-burpsuite-extension/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jsmonhq","download_url":"https://codeload.github.com/jsmonhq/jsmon-burpsuite-extension/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsmonhq%2Fjsmon-burpsuite-extension/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29047826,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-03T14:55:20.264Z","status":"ssl_error","status_checked_at":"2026-02-03T14:55:19.725Z","response_time":96,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["burpsuite","extension","jsmon"],"created_at":"2026-02-03T15:17:40.717Z","updated_at":"2026-02-03T15:17:40.842Z","avatar_url":"https://github.com/jsmonhq.png","language":"Java","funding_links":[],"categories":[],"sub_categories":[],"readme":"# JSMon Burp Suite Extension\n\nA powerful Burp Suite extension that automatically scans scannable files using the JSMon API. Discover secrets, API endpoints, domains, and other intelligence from web files as you browse.\n\n![JSMon Burp Suite Extension Interface](images/image.png)\n\n## Features\n\n- 🔑 **Easy API Key Configuration** - Enter your JSMon API key directly in the extension\n- 📁 **Workspace Management** - Fetch existing workspaces or create new ones\n- 🌐 **Domain Scoping** - Limit scanning to specific domains (includes subdomains)\n- ⚡ **Automatic Scanning** - Automatically scan scannable files as you browse\n- 📊 **Intelligence Dashboard** - View secrets, JS URLs, API paths, domains, IPs, emails, S3 buckets, and more\n- 📋 **Copy to Clipboard** - One-click copy for all intelligence data\n- 🔄 **Real-time Updates** - See scan results and counts update in real-time\n- 🎨 **Dark/Light Theme Support** - Automatically adapts to Burp Suite's theme\n\n## Requirements\n\n- Burp Suite Professional or Community Edition (2024.1 or later)\n- Java 11 or higher\n- JSMon API account and API key\n\n## Installation\n\n1. Download the latest `jsmon-burp-extension-1.1.0.jar` file\n2. Open Burp Suite\n3. Go to the **Extensions** tab\n4. Click the **Add** button\n5. Select **Extension type**: Java\n6. Click **Select file** and choose the downloaded JAR file\n7. Verify the extension loads without errors in the **Output** tab\n8. You should see a new **JSMon** tab in Burp Suite\n\n## Quick Start Guide\n\n### Step 1: Configure API Key\n\n1. Open the **JSMon** tab in Burp Suite\n2. Enter your JSMon API key in the \"🔑 API Key\" field\n3. Click **Fetch Workspaces** to retrieve your workspaces\n4. Your user profile (name, email, JSScan credits) will be displayed automatically\n\n### Step 2: Select or Create Workspace\n\n- **Select Existing Workspace**: Choose a workspace from the dropdown\n- **Create New Workspace**: Enter a name and click **Create**\n\n### Step 3: Configure Domain Scoping (Optional)\n\n- Enter domain(s) in the \"🌐 Domain Scoping\" field (one per line or comma-separated)\n- Leave empty to scan all files regardless of domain\n- Subdomains are automatically included (e.g., `example.com` includes `sub.example.com`)\n\n### Step 4: Enable Automatic Scanning\n\n- Check **Enable Automatic Scanning** to automatically scan scannable files as you browse\n- When enabled, the extension will:\n  - Scan all existing scannable files in Burp's history\n  - Automatically process new scannable files as you browse\n  - Respect your domain scoping settings\n\n### Step 5: View Intelligence Data\n\n- Click on the **📊 JS-Intelligence Data** tab to view:\n  - 🔐 **Secrets** - API keys, tokens, and other secrets found\n  - 🔗 **JS URLs** - All JavaScript files discovered\n  - 🛣️ **API Paths** - API endpoints extracted from files\n  - 🔗 **URLs** - All URLs found in files\n  - 🌐 **Domains** - Domains discovered\n  - 🌐 **IP Addresses** - IP addresses found\n  - 📧 **Emails** - Email addresses discovered\n  - 🪣 **S3 Buckets** - S3 bucket names found\n  - 📦 **Invalid Node Modules** - NPM confusion packages detected\n\n## Usage\n\n### Automatic Scanning\n\nWhen automatic scanning is enabled:\n- The extension monitors all HTTP responses in Burp Suite\n- Scannable files are automatically detected (by file extension or `Content-Type` header)\n- Files are sent to JSMon API with all relevant headers (User-Agent, Cookie, Authorization, etc.)\n- Each URL is processed only once to avoid duplicates\n- Results appear in real-time in the intelligence tabs\n\n### Manual Scanning\n\n1. Click **🚀 Start Manual Scan** to scan all scannable files from Burp's HTTP history\n2. Progress is shown in the status log\n3. Results are automatically displayed in the intelligence tabs\n\n### Viewing Intelligence Data\n\n- **Secrets Tab**: View all secrets found (API keys, tokens, etc.)\n- **JS Intelligence Tabs**: Browse through different types of intelligence data\n- **Counts**: Each tab shows the total count in parentheses (e.g., \"📧 Emails (188)\")\n- **Pagination**: Use **◀ Prev** and **Next ▶** buttons to navigate through pages\n- **Copy All**: Click **📋 Copy All** button to copy all data from a tab to clipboard\n\n### Copying Data\n\n- **Copy Selected Cells**: Select cells in any table and press `Ctrl+C` (or `Cmd+C` on Mac)\n- **Copy All Data**: Click the **📋 Copy All** button at the bottom of each intelligence tab\n  - This copies all values from the first column (the actual data, not timestamps)\n  - Data is copied one item per line, ready to paste anywhere\n\n## Configuration Options\n\n| Option | Description |\n|--------|-------------|\n| **API Key** | Your JSMon API key (required) |\n| **Workspace** | The workspace where scan results will be stored (required) |\n| **Scoped Domain** | Domain(s) to limit scanning scope. Leave empty to scan all domains |\n| **Automatic Scanning** | Enable/disable automatic scanning of scannable files |\n\n## Understanding the Intelligence Data\n\n### Secrets\nAPI keys, tokens, passwords, and other sensitive information found in files.\n\n### JS URLs\nAll file URLs that have been scanned. Useful for identifying all scannable files in scope.\n\n### API Paths\nAPI endpoints and paths extracted from files. Great for discovering hidden endpoints.\n\n### URLs\nAll URLs found in files, including internal and external links.\n\n### Domains\nAll domains discovered in files. Helps identify all domains used by the application.\n\n### IP Addresses\nIP addresses found in files, including internal and external IPs.\n\n### Emails\nEmail addresses discovered in files. Useful for identifying contacts and user emails.\n\n### S3 Buckets\nAmazon S3 bucket names found in files. Can reveal misconfigured or exposed buckets.\n\n### Invalid Node Modules\nNPM confusion packages detected - packages with typosquatting or suspicious names.\n\n## Status Log\n\nThe status log at the bottom shows:\n- Configuration changes\n- Scan progress\n- API responses\n- Errors and warnings\n- Copy operations\n\n## Troubleshooting\n\n### Extension Not Loading\n- Ensure you're using Burp Suite 2024.1 or later\n- Check that Java 11+ is installed\n- Verify the JAR file is not corrupted\n- Check the **Output** tab in Burp Suite for error messages\n\n### Workspaces Not Fetching\n- Verify your API key is correct\n- Check your internet connection\n- Look for error messages in the status log\n\n### Files Not Being Scanned\n- Ensure **Automatic Scanning** is enabled\n- Check that the domain matches your scoped domain (if set)\n- Verify the workspace is selected\n- Check the status log for any error messages\n\n### Counts Showing Zero\n- Counts are fetched automatically when you select a workspace\n- If counts are zero, try:\n  - Selecting the workspace again\n  - Clicking on the intelligence tabs to refresh data\n  - Checking if there's actual data in your workspace\n\n### Copy Not Working\n- Ensure you have data loaded in the table\n- Try selecting cells first, then copying\n- Use the **Copy All** button for bulk copying\n\n## Tips \u0026 Best Practices\n\n1. **Start with Domain Scoping**: Limit your scans to your target domain to avoid scanning unrelated files\n2. **Monitor JSScan Credits**: Check your remaining credits in the User section\n3. **Use Manual Scan First**: Run a manual scan to see what data is available before enabling automatic scanning\n4. **Export Data Regularly**: Use the Copy All buttons to export data for further analysis\n5. **Check Secrets First**: Always review the Secrets tab first as it contains the most critical findings\n\n## Version\n\n**Current Version**: 1.1.0\n\n## Support\n\nFor issues, questions, or feature requests, please check the extension's status log for detailed error messages.\n\n## License\n\nThis extension is provided as-is for use with JSMon API.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjsmonhq%2Fjsmon-burpsuite-extension","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjsmonhq%2Fjsmon-burpsuite-extension","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjsmonhq%2Fjsmon-burpsuite-extension/lists"}