An open API service indexing awesome lists of open source software.

awesome-burp-extensions

A curated list of amazingly awesome Burp Extensions
https://github.com/snoopysecurity/awesome-burp-extensions

Last synced: 8 days ago
JSON representation

  • Beautifiers and Decoders

    • XChromeLogger Decoder - his extension adds a new tab in the HTTP message editor to display X-ChromeLogger-Data in decoded form.
    • WebSphere Portlet State Decoder - This extension displays the decoded XML state of a WebSphere Portlet in a new tab when the request is viewed.
    • PDF Viewer - This extension adds a tab to the HTTP message viewer to render PDF files in responses.
    • NTLM Challenge Decoder - This extension decodes NTLM SSP headers.
    • JCryption Handler - This extension provides a way to perform manual and/or automatic Security Assessment for Web Applications that using JCryption JavaScript library to encrypt data sent through HTTP methods (GET and POST).
    • JSWS Parser - This extension can be used to parse a response containing a JavaScript Web Service Proxy (JSWS) and generate JSON requests for all supported methods.
    • JSON Decoder - This extension adds a new tab to Burp's HTTP message editor, and displays JSON messages in decoded form.
    • MessagePack - This extension supports: decoding MessagePack requests and responses to JSON format, converting requests from JSON format to MessagePack.
    • Fast Infoset Tester - This extension converts incoming Fast Infoset requests and responses to XML, and converts outgoing messages back to Fast Infoset.
    • BurpAMFDSer - BurpAMFDSer is a Burp plugin that will deserialze/serialize AMF request and response to and from XML with the use of Xtream library.
    • Cyber Security Transformation Chef - The Cyber Security Transformation Chef (CSTC) is a Burp Suite extension. It is build for security experts to extend Burp Suite for chaining simple operations for each incomming or outgoing message.
    • .NET Beautifier - A BurpSuite extension for beautifying .NET message parameters and hiding some of the extra clutter that comes with .NET web apps (i.e. __VIEWSTATE).
    • JS Beautifier - Burp Suite JS Beautifier
    • Burp ASN1 Toolbox - ASN.1 toolbox for Burp Suite.
    • JSON JTree viewer for Burp Suite - JSON JTree viewer for Burp Suite.
    • JSON Beautifier - JSON Beautifier for Burp written in Java
    • Browser Repeater - BurpSuite extension for Repeater tool that renders responses in a real browser.
    • GQL Parser - A repository for GraphQL Extension for Burp Suite
    • burp-protobuf-decoder - A simple Google Protobuf Decoder for Burp
    • Deflate Burp Plugin - The Deflate Burp Plugin is a plug-in for Burp Proxy (it implements the IBurpExtender interface) that decompresses HTTP response content in the ZLIB (RFC1950) and DEFLATE (RFC1951) compression formats.
    • Burp Suite GWT wrapper - Burp Suite GWT wrapper
    • GraphQL Beautifier - Burp Suite extension to help make Graphql request more readable.
    • Decoder Improved - Improved decoder for Burp Suite.
    • GraphQL Raider - GraphQL Raider is a Burp Suite Extension for testing endpoints implementing GraphQL.
    • burp-suite-jsonpath - Burp Suite extension to view and extract data from JSON responses.
    • Burp Beautifier - BurpBeautifier is a Burpsuite extension for beautifying request/response body, supporting JS, JSON, HTML, XML format, writing in Jython 2.7.
    • JSON/JS Beautifier - This is a Burp Extension for beautifying JSON and JavaScript output to make the body parameters more human readable.
    • Burp-Timestamp-Editor - Provides a GUI to view and edit Unix timestamps in Burp message editors.
    • ViewState Editor - This extension allows Burp users to view & edit the contents of ViewState.
  • Burp Extension Training Resources

  • Cloud Security

    • AWS Security Checks - This extensions provides additional Scanner checks for AWS security issues.
    • AWS Extender - AWS Extender (Cloud Storage Tester) is a Burp plugin to assess permissions of cloud storage containers on AWS, Google Cloud and Azure.
    • AWS Signer - Burp Extension for AWS Signing.
    • cloud_enum - Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud. Must be run from a *nix environment.
    • Burp-AnonymousCloud - Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities.
    • AWS Cognito - This extension helps identify key information from requests to AWS Cognito, provides several passive scan checks, and suggests HTTP request templates for exploiting several known vulnerabilities.
    • AWS SigV4 - This is a Burp extension for signing AWS requests with SigV4.
  • Cryptography

    • SSRF

      • Length Extension Attacks - This extension lets you perform hash length extension attacks on weak signature mechanisms.
      • WhatsApp Protocol Decryption Burp Tool - This tool was created during our research on Whatsapp Protocol.
      • AES Burp/AES Payloads - Burp Extension to manipulate AES encrypted payloads.
      • Crypto Attacker - The extension helps detect and exploit some common crypto flaws.
      • AES Killer - Burp plugin to decrypt AES Encrypted traffic of mobile apps on the fly.
      • Resign v2.0 - A burp extender that recalculate signature value automatically after you modified request parameter value.but you need to know the signature algorithm detail and configure at GUI.
      • BurpCrypto - Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).
      • Padding Oracle Hunter - Padding Oracle Hunter is a Burp Suite extension that helps penetration testers quickly identify and exploit the PKCS#7 and PKCS#1 v1.5 padding oracle vulnerability.
      • PyCript - Burp Suite extension that allows for bypassing client-side encryption using custom logic for manual and automation testing with Python and NodeJS. It enables efficient testing of encryption methods and identification of vulnerabilities in the encryption process.
      • Add To TLS Pass Through Extension - Burp Extension to add context menus for configuration of the Add to TLS Pass Through setting
      • TLS-Attacker-BurpExtension - The extension is based on the TLS-Attacker and developed by the Chair for Network and Data Security from the Ruhr-University Bochum to assist pentesters and security researchers in the evaluation of TLS Server configurations with Burp Suite.
  • Custom Features

    • Scan Manual Insertion Point - This Burp extension lets the user select a region of a request (typically a parameter value), and via the context menu do an active scan of just the insertion point defined by that selection.
    • Distribute Damage - Designed to make Burp evenly distribute load across multiple scanner targets, this extension introduces a per-host throttle and a context menu to trigger scans from.
    • Decoder Improved - Decoder Improved is a data transformation plugin for Burp Suite that better serves the varying and expanding needs of information security professionals.
    • Request Minimizer - This extension performs HTTP request minimization. It deletes parameters that are not relevant such as: random ad cookies, cachebusting nonces, etc.
    • Multi-Browser Highlighting - This extension highlights the Proxy history to differentiate requests made by different browsers. The way this works is that each browser would be assigned one color and the highlights happen automatically.
    • Manual Scan Issues - This extension allows users to manually create custom issues within the Burp Scanner results.
    • Handy Collaborator - Handy Collaborator is a Burp Suite Extension that lets you use the Collaborator tool during manual testing in a comfortable way.
    • HAR Importer - A HAR importer.
    • Burp Bounty - Scan Check Builder - This BurpSuite extension allows you, in a quick and simple way, to improve the active and passive burpsuite scanner by means of personalized rules through a very intuitive graphical interface.
    • Decoder Pro - Burp Suite Plugin to decode and clean up garbage response text.
    • Request Highlighter - Request Highlighter is a simple extension for Burp Suite tool (for both community and professional editions) that provides an automatic way to highlight HTTP requests based on headers content (eg. Host, User-Agent, Cookies, Auth token, custom headers etc.).
    • Wildcard - There is number of great Burp extension out there. Most of them create their own tabs.
    • Hackvertor - Hackvertor is a tag-based conversion tool that supports various escapes and encodings including HTML5 entities, hex, octal, unicode, url encoding etc.
    • Custom Send To - Adds a customizable "Send to..."-context-menu to your BurpSuite.
    • IP Rotate - Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.
    • Auto Drop - This extension allows you to automatically Drop requests that match a certain regex. Helpful in case the target has logging or tracking services enabled.
    • Taborator - Improved Collaborator client in its own tab.
    • pip3line - Raw bytes manipulation utility, able to apply well known and less well known transformations.
    • Response Pattern Matcher - Adds extensibility to Burp by using a list of payloads to pattern match on HTTP responses highlighting interesting and potentially vulnerable areas.
    • Add & Track Custom Issues - This extension allows custom scan issues to be added and tracked within Burp.
    • Piper for Burp Suite - Piper Burp Suite Extender plugin.
    • Response Grepper - This Burp extension will auto-extract and display values from HTTP Response bodies based on a Regular Expression.
    • Attack Surface Detector - The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters.
    • Timeinator - Timeinator is an extension for Burp Suite that can be used to perform timing attacks over an unreliable network such as the internet.
    • Copy Request & Response - The Copy Request & Response Burp Suite extension adds new context menu entries that can be used to simply copy the request and response from the selected message to the clipboard.
    • HaE - Highlighter and Extractor - HaE is used to highlight HTTP requests and extract information from HTTP response messages.
    • Burp-IndicatorsOfVulnerability - Burp extension that checks application requests and responses for indicators of vulnerability or targets for attack
    • BurpSuiteSharpener - This extension should add a number of UI and functional features to Burp Suite to make working with it easier.
    • Burp-Send-To-Extension - Adds a customizable "Send to..."-context-menu to your BurpSuite.
    • Reshaper for Burp - Extension for Burp Suite to trigger actions and reshape HTTP request and response traffic using configurable rules
    • RepeaterClips - The RepeaterClips extension lets you share requests with just two clicks and a paste.
    • Copy Regex Matches - Copy Regex Matches is a Burp Suite plugin to copy regex matches from selected requests and/or responses to the clipboard.
    • match-replace-burp - Useful Match and Replace BurpSuite Rules
    • Backup Finder - A burp suite extension that reviews backup, old, temporary, and unreferenced files on the webserver for sensitive information.
    • Diff Last Response - Diff last response will show the difference between the previous and current response.
    • WebAuthn CBOR Decoder - WebAuthn CBOR is a Burp Extension to decode WebAuthn CBOR format. WebAuthn is a W3C Standard to support strong authentication of users.
    • SocketSleuth - Burp Extension to add additional functionality for pentesting websocket based applications
    • WebSocket Turbo Intruder - Extension to fuzz WebSocket messages using custom code
    • Conditional Match and Replace (CMAR) - An extension allowing you to create match and replace operations that execute only when a condition is matched (or not matched). The condition can be matched against the request Header/Body/All, or the response Header/Body/All. If the condition is matched, you can apply a match and replace rule against the specified area. You can create a condition that matches a request, then performs a match and replace in the response.
    • BlazorTrafficProcessor (BTP) - A BurpSuite extension to aid pentesting web applications that use Blazor Server/BlazorPack. Primary functionality includes converting BlazorPack messages to JSON and vice versa, introduces tamperability for BlazorPack serialized messages.
    • MagicByteSelector - Burp Suite Extension for inserting a magic byte into responder's request
    • CookieMonster - A Burp Suite plugin to easily manage cookies
    • DNS-Exfilnspector - Automagically decode DNS Exfiltration queries to convert Blind RCE into proper RCE via Burp Collaborator
    • BatchRepeater - BatchRepeater is a BurpSuite extension that enhances the functionality of the Repeater tool by allowing users to send multiple selected HTTP requests to the Repeater in a single action.
    • PyCript WebSocket - PyCript WebSocket is a Burp Suite extension that enables users to encrypt and decrypt WebSocket messages.
    • BadIntent - Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite.
    • PyCript WebSocket - PyCript WebSocket is a Burp Suite extension that enables users to encrypt and decrypt WebSocket messages.
    • Add & Track Custom Issues - This extension allows custom scan issues to be added and tracked within Burp.
    • Timeinator - Timeinator is an extension for Burp Suite that can be used to perform timing attacks over an unreliable network such as the internet.
    • PwnFox - PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.
    • reDOM - reDOM is Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy applications built with frameworks like ReactJS, VueJS, Angular, and more.
  • Information Gathering

    • Google Hack - This extension provides a GUI interface for setting up and running Google Hacking queries, and lets you add results directly to Burp's site map..
    • Site Map Extractor - This extension extracts information from the Site Map. You can use the full site map or just in-scope items.
    • Site Map Fetcher - This extension fetches the responses of unrequested items in the site map.
    • Attack Surface Detector - The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters.
    • PwnBack/Wayback Machine - Burp Extender plugin that generates a sitemap of a website using Wayback Machine.
    • Directory File Listing Parser Importer - This is a Burp Suite extension in Python to parse a directory and file listing text file of a web application.
    • Burp CSJ - This extension integrates Crawljax, Selenium and JUnit together. The intent of this extension is to aid web application security testing, increase web application crawling capability and speed-up complex test-cases execution.
    • domain_hunter - A Burp Suite extender that try to find sub-domains,similar domains and related domains of an organization, not only domain.
    • BigIP Discover - A extension of Burp suite. The cookie set by the BipIP server may include a private IP, which is an extension to detect that IP
    • Asset Discover - Burp Suite extension to discover assets from HTTP response using passive scanning.
    • Dr. Watson - Dr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful information.
    • Subdomain Extractor - A very simple, straightforward extension to export sub domains from Burp using a context menu option.
    • SAN Scanner - SAN Scanner is a Burp Suite extension for enumerating associated domains & services via the Subject Alt Names section of SSL certificates.
    • Add to sitemap++ - Add to sitemap++ is a BURP extension that can read URLs from files or clipboard and add the discovered information on the site map of the selected host(s).
    • Look Over There - This is a Burp Suite extension to help Burp know where to look during scanning.
  • Logging and Notes

    • SSRF

      • Flow - This extension provides a Proxy history-like view along with search filter capabilities for all Burp tools.
      • Custom Logger - This extension adds a new tab to Burp's main UI containing a simple log of all requests made by all Burp tools.
      • Notes - This extension adds a new tab to Burp's UI, for taking notes and organizing external files that are created during penetration testing.
      • Log Requests to SQLite - This extension keeps a trace of every HTTP request that has been sent via BURP, in an SQLite database. This is useful for keeping a record of exactly what traffic a pen tester has generated.
      • Burp Savetofile - BurpSuite plugin to save just the body of a request or response to a file
      • Bookmarks - A Burp Suite extension to bookmark requests for later, instead of those 100 unnamed repeater tabs you've got open.
      • Burp Scope Monitor Extension - A Burp Suite Extension to monitor and keep track of tested endpoints.
      • Burp Notes - Burp Notes Extension is a plugin for Burp Suite that adds a Notes tab. The tool aims to better organize external files that are created during penetration testing..
      • Burp Dump - A Burp plugin to dump HTTP(S) requests/responses to a file system.
      • Burp SQLite logger - SQLite logger for Burp Suite.
      • Burp Git Version - Description not available.
      • Burp Commentator - Generates comments for selected request(s) based on regular expressions.
      • Burp Suite Importer - Connect to multiple web servers while populating the sitemap.
      • Burp Replicator - Burp extension to help developers replicate findings from pen tests.
      • Log Requests to SQLite - BURP extension to record every HTTP request send via BURP and create an audit trail log of an assessment.
      • Burp Response Clusterer - Burp plugin that clusters responses to show an overview of received responses.
      • Burp Collect500 - Burp plugin that collects all HTTP 500 messages.
      • Sink Logger - Sink Logger is a Burp Suite Extension that allows to transparently monitor various JavaScript sinks.
      • Log Viewer - Lets you view log files generated by Burp in a graphical enviroment.
      • Rapid - A fairly simple Burp Suite extension that enables you to save HTTP Requests and Responses to files a lot faster and in one go.
      • Scope Monitor - A Burp Suite Extension to monitor and keep track of tested endpoints.
      • Progress Tracker - Burp Suite extension to track vulnerability assessment progress.
      • Pentest Mapper - A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities and write test cases for each flow, API and http request.
      • Logger++ - Burp Suite Logger++: Log activities of all the tools in Burp Suite.
      • Burp Savetofile - BurpSuite plugin to save just the body of a request or response to a file
  • Misc

    • SSRF

      • Target Redirector - This extension allows you to redirect requests to a particular target by replacing an incorrect target hostname/IP with the intended one. The Host header can optionally also be updated.
      • Similar Request Excluder - Similar Request Excluder is an extension that enables you to automatically reduce the target scope of your active scan by excluding similar (and therefore redundant) requests.
      • Replicator - Replicator helps developers to reproduce issues discovered by pen testers.
      • GWT Insertion Points - This extension automatically identifies insertion points for GWT (Google Web Toolkit) requests when sending them to the active Scanner or Burp Intruder.
      • Headless Burp - This extension allows you to run Burp Suite's Spider and Scanner tools in headless mode via the command-line.
      • HTTP Mock - This Burp extension provides mock responses that can be customized, based on the real ones.
      • Batch Scan Report Generator - This extension can be used to generate multiple scan reports by host with just a few clicks.
      • Decompressor - Often, HTTP traffic is compressed by the server before it is sent to the client in order to reduce network load.
      • CVSS Calculator - This extension calculates CVSS v2 and v3 scores of vulnerabilities.
      • Request Timer - This extension captures response times for requests made by all Burp tools. It could be useful in uncovering potential timing attacks.
      • Response Clusterer - This extension clusters similar responses together, and shows a summary with one request/response per cluster. This allows the tester to get an overview of the tested website's responses from all Burp Suite tools.
      • Kerberos Authentication - This extension provides support for performing Kerberos authentication. This is useful for testing in a Windows domain when NTLM authentication is not supported.
      • JVM Property Editor - This extension allows the user to view and modify JVM system properties while Burp is running.
      • Lair - This extension provides the facility to send Burp Scanner issues directly to a remote Lair project.
      • Google Authenticator - This Burp Suite extension turns Burp into a Google Authenticator client.
      • Carbonator - This extension provides a command-line interface to automate the process of configuring target scope, spidering and scanning.
      • Custom Parameter Handler - This extension provides a simple way to modify any part of an HTTP message, allowing manipulation with surgical precision even (and especially) when using macros.
      • Proxy Auto Config - This extension automatically configures Burp upstream proxies to match desktop proxy settings.
      • Curlit - Burp Python plugin to turn requests into curl commands.
      • Burp Customizer - This extension allows you to use these themes in Burp Suite, and includes a number of bundled themes to try.
      • Filter Options Method - Burp extension that filters out OPTIONS requests from populating Burp's Proxy history.
      • Hackbar - HackBar plugin for Burpsuite v1.0.
      • knife - A burp extension that add some useful function to Context Menu. This includes *one key to update cookie*, *one key add host to scope* to the right click context menu, *insert payload* of Hackbar or self-configured to current request.
      • Burp Rest API - REST/JSON API to the Burp Suite security tool.
      • Burpa - A Burp Suite Automation Tool.
      • Burp Uniqueness - Uniqueness plugin for Burp Suite.
      • Sample Burp Suite extension: custom scanner checks - Sample Burp Suite extension: custom scanner checks
      • Burp Bing translator - Testing non-English web apps is pretty straight forward which you can just use browser extension to translate what you see on screens.
      • Similar Request Excluder - A Burp Suite extension that automatically marks similar requests as 'out-of-scope'.
      • jython-burp-api - Develop Burp extensions in Jython.
      • Jython Burp Extensions - Description not available.
      • Add Custom Header - A Burp Suite extension to add a custom header (e.g. JWT).