An open API service indexing awesome lists of open source software.

Projects in Awesome Lists tagged with burp-plugin

A curated list of projects in awesome lists tagged with burp-plugin .

https://github.com/aress31/burpgpt

A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.

ai burp-extensions burp-plugin burpsuite burpsuite-extender cybersecurity gpt gpt-3 openai openai-api pentesting security security-automation webapp

Last synced: 15 May 2025

https://github.com/bit4woo/knife

A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅

burp burp-extensions burp-plugin burpsuite burpsuite-extender cookie hackbar header-edit http-edit knife menu u2c unicode-to-chinese update-cookie

Last synced: 14 May 2025

https://github.com/f0ng/captcha-killer-modified

captcha-killer的修改版,支持关键词识别base64编码的图片,添加免费ocr库,用于验证码爆破,适配新版Burpsuite

burp burp-extensions burp-plugin

Last synced: 14 May 2025

https://github.com/whwlsfb/burpcrypto

BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件

burp-extensions burp-plugin burpcrypto burpsuite burpsuite-extender ctf ctf-tools execute-js-encryption fuzz-testing payloads

Last synced: 16 May 2025

https://github.com/whwlsfb/BurpCrypto

BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件

burp-extensions burp-plugin burpcrypto burpsuite burpsuite-extender ctf ctf-tools execute-js-encryption fuzz-testing payloads

Last synced: 13 May 2025

https://github.com/f0ng/autodecoder

Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

burp burp-plugin burpsuite-extender

Last synced: 08 Oct 2025

https://github.com/vaycore/OneScan

OneScan 是一款用于递归目录扫描的 BurpSuite 插件

burp burp-extensions burp-plugin burpsuite burpsuite-extender dir-fuzz dir-scanner dir-search dirscan fuzz

Last synced: 07 Sep 2025

https://github.com/f0ng/autoDecoder

Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

burp burp-plugin burpsuite-extender

Last synced: 11 Jul 2025

https://github.com/Quitten/Autorize

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests

application-security authorization authorization-enforcement burp-plugin burpsuite jython

Last synced: 02 Apr 2025

https://github.com/quitten/autorize

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests

application-security authorization authorization-enforcement burp-plugin burpsuite jython

Last synced: 02 Apr 2025

https://github.com/c0ny1/captcha-killer

burp验证码识别接口调用插件

burp-extensions burp-plugin burpsuite-extender captcha

Last synced: 04 Apr 2025

https://github.com/nccgroup/autorepeater

Automated HTTP Request Repeating With Burp Suite

burp-plugin burpsuite security

Last synced: 25 Oct 2025

https://github.com/nccgroup/AutoRepeater

Automated HTTP Request Repeating With Burp Suite

burp-plugin burpsuite security

Last synced: 19 Apr 2025

https://github.com/outlaws-bai/Galaxy

一个想让你测试加密流量像测试明文一样简单高效的 Burp 插件。 A Burp plugin that makes testing encrypted traffic as simple and efficient as testing plaintext.

burp-plugin burpsuite burpsuite-extender encrypted-messages pentest

Last synced: 31 Oct 2025

https://github.com/f0ng/log4j2burpscanner

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

burp-extensions burp-plugin log4j2 log4jshell

Last synced: 04 Apr 2025

https://github.com/bit4woo/recaptcha

reCAPTCHA = REcognize CAPTCHA: A Burp Suite Extender that recognize CAPTCHA and use for intruder payload 自动识别图形验证码并用于burp intruder爆破模块的插件

burp-extensions burp-plugin burpsuite captcha intruder recaptcha recognize-captcha recognizes-images

Last synced: 12 Apr 2025

https://github.com/bit4woo/reCAPTCHA

reCAPTCHA = REcognize CAPTCHA: A Burp Suite Extender that recognize CAPTCHA and use for intruder payload 自动识别图形验证码并用于burp intruder爆破模块的插件

burp-extensions burp-plugin burpsuite captcha intruder recaptcha recognize-captcha recognizes-images

Last synced: 19 Apr 2025

https://github.com/synacktiv/HopLa

HopLa Burp Suite Extender plugin - Adds autocompletion support and useful payloads in Burp Suite

burp burp-extensions burp-plugin burp-suite burp-ui

Last synced: 13 May 2025

https://github.com/bit4woo/domain_hunter

A Burp Suite Extension that try to find all sub-domain, similar-domain and related-domain of an organization automatically! 基于流量自动收集整个企业或组织的子域名、相似域名、相关域名的burp插件

burp-extensions burp-plugin burpsuite-extender certificate certification domain-discovery domain-hunter domains https-certificate organization-domain related-domain similar-domain sitemap spider subdomain subject-alternative-name subject-name subjectaltname

Last synced: 04 Apr 2025

https://github.com/Acmesec/Sylas

新一代子域名主/被动收集工具 - Subdomain automatic/passive collection tool

burp-extensions burp-plugin burpsuite-extender burpsuite-tools scan scanner scanner-web subdomain-finder subdomain-scanner

Last synced: 11 Jul 2025

https://github.com/doyensec/burpdeveltraining

Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"

burp-plugin burpsuite java security-automation training-materials

Last synced: 07 Apr 2025

https://github.com/bit4woo/u2c

Unicode To Chinese -- U2C : A burpsuite Extender That Convert Unicode To Chinese 【Unicode编码转中文的burp插件】

burp-extensions burp-plugin burpsuite-extender chinese unicode

Last synced: 07 May 2025

https://github.com/theLSA/burp-unauth-checker

burpsuite extension for check unauthorized vulnerability

burp-plugin burpsuite checker unauthenticated vulnerability

Last synced: 11 Jul 2025

https://github.com/usdAG/cstc

CSTC is a Burp Suite extension that allows request/response modification using a GUI analogous to CyberChef

burp-extensions burp-plugin burpsuite cyberchef encoding extender java transformation

Last synced: 19 Apr 2025

https://github.com/h3xstream/burp-retire-js

Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.

burp-plugin javascript maven scanner vulnerability zap-plugin

Last synced: 16 May 2025

https://github.com/saoshao/DetSql

Burp插件,快速探测可能存在SQL注入的请求并标记,提高测试效率

burp-extensions burp-plugin burpsuite-extender

Last synced: 03 Aug 2025

https://github.com/AresS31/swurg

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their official BApp Store).

burp-extensions burp-plugin burpsuite json openapi openapi-client openapi-specification openapi2 openapi3 parser pentesting restful-api swagger yaml

Last synced: 21 Feb 2025

https://github.com/aress31/openapi-parser

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their official BApp Store).

burp-extensions burp-plugin burpsuite json openapi openapi-client openapi-specification openapi2 openapi3 parser pentesting restful-api swagger yaml

Last synced: 09 Apr 2025

https://github.com/simioni87/auth_analyzer

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

application-security auth authorization burp-extensions burp-plugin burpsuite pentest-tool portswigger

Last synced: 13 May 2025

https://github.com/moloch--/CSP-Bypass

A Burp Plugin for Detecting Weaknesses in Content Security Policies

burp-plugin content-security-policy csp security

Last synced: 19 Apr 2025

https://github.com/moloch--/csp-bypass

A Burp Plugin for Detecting Weaknesses in Content Security Policies

burp-plugin content-security-policy csp security

Last synced: 20 Aug 2025

https://github.com/xer0times/SQLi-Query-Tampering

SQLi Query Tampering extends and adds custom Payload Generator/Processor in Burp Suite's Intruder. This extension gives you the flexibility of manual testing with many powerful evasion techniques.

bug-bounty bugbounty bughunting burp-extensions burp-plugin burpsuite burpsuite-pro evasion payload-generator pentesting pentesting-tools sqli sqlinjection

Last synced: 07 Sep 2025

https://github.com/GoSecure/csp-auditor

Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website

burp burp-plugin csp hacktoberfest http security zap zap-plugin

Last synced: 31 Mar 2025

https://github.com/gosecure/csp-auditor

Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website

burp burp-plugin csp hacktoberfest http security zap zap-plugin

Last synced: 05 Apr 2025

https://github.com/hvqzao/burp-wildcard

Burp extension intended to compact Burp extension tabs by hijacking them to own tab.

burp burp-extensions burp-plugin burpsuite

Last synced: 19 Apr 2025

https://github.com/silentsignal/burp-piper

Piper Burp Suite Extender plugin

burp-extensions burp-plugin burpsuite-extender

Last synced: 19 Apr 2025

https://github.com/Anof-cyber/Pentest-Mapper

A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabilities

appsec bugbounty burp burp-extensions burp-plugin burpsuite burpsuite-extender burpsuite-tools infosec pentesting

Last synced: 13 May 2025

https://github.com/thomaspatzke/wase

The Web Audit Search Engine - Index and Search HTTP Requests and Responses in Web Application Audits with ElasticSearch

burp burp-plugin elasticsearch pentesting webappsec

Last synced: 17 Mar 2025

https://github.com/anof-cyber/pentest-mapper

A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabilities

appsec bugbounty burp burp-extensions burp-plugin burpsuite burpsuite-extender burpsuite-tools infosec pentesting

Last synced: 07 Apr 2025

https://github.com/theLSA/burp-sensitive-param-extractor

burpsuite extension for check and extract sensitive request parameter

burp-plugin burpsuite checker extractor parameters sensitive

Last synced: 09 Aug 2025

https://github.com/BitTheByte/BitBlinder

BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS vulnerabilities

burp-extensions burp-plugin burpsuite burpsuite-extender jython python

Last synced: 02 Apr 2025

https://github.com/keramas/mssqli-duet

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

active-directory application-security burp-extensions burp-plugin mssql penetration-testing sql-injection user-enumeration windows

Last synced: 19 Oct 2025

https://github.com/Keramas/mssqli-duet

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

active-directory application-security burp-extensions burp-plugin mssql penetration-testing sql-injection user-enumeration windows

Last synced: 02 Apr 2025

https://github.com/javeleyqaq/sql-injection-scout

SQL Injection Scout 是一个用于 Burp Suite 的扩展,专为帮助安全研究人员和开发人员检测和分析 SQL 注入漏洞而设计。该扩展提供了丰富的配置选项和直观的用户界面,便于用户自定义扫描和分析过程。

burp burp-extensions burp-plugin burpsuite sqlinject sqlinjection sqlinjectionattack

Last synced: 05 Mar 2025

https://github.com/tkmru/lazyCSRF

A more useful CSRF PoC generator on Burp Suite

arsenal blackhat burp-extensions burp-plugin burpsuite csrf

Last synced: 11 Jul 2025

https://github.com/theLSA/burp-info-extractor

burpsuite extension for extract information from data

burp-plugin burpsuite extractor information

Last synced: 11 Jul 2025

https://github.com/gnothiseautonlw/burp-shell-fwd-lfi

A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration

burp-extensions burp-plugin burpsuite burpsuite-extender penetration-testing penetration-testing-tools pentesting security security-tools

Last synced: 11 Jul 2025

https://github.com/thomashartm/burp-aem-scanner

Burp Scanner extension to fingerprint and actively scan instances of the Adobe Experience Manager CMS. It checks the website for common misconfigurations and security holes.

adobe-experience-manager aem burp burp-extensions burp-plugin dispatcher java security-audit security-automation

Last synced: 16 Mar 2025

https://github.com/augustd/burp-suite-error-message-checks

Burp Suite extension to passively scan for applications revealing server error messages

burp burp-extensions burp-plugin burpsuite java penetration-testing pentest scanning

Last synced: 19 Apr 2025

https://github.com/aress31/flarequench

Burp Suite plugin that adds additional checks to the passive scanner to reveal the origin IP(s) of Cloudflare-protected web applications.

burp-extensions burp-plugin burpsuite cloudflare cloudflare-bypass crimeflare

Last synced: 22 Mar 2025

https://github.com/chopicalqui/TurboDataMiner

The objective of this Burp Suite extension is the flexible and dynamic extraction, correlation, and structured presentation of information from the Burp Suite project as well as the flexible and dynamic on-the-fly modification of outgoing or incoming HTTP requests using Python scripts. Thus, Turbo Data Miner shall aid in gaining a better and faster understanding of the data collected by Burp Suite.

burp burp-api burp-extensions burp-plugin burpsuite burpsuite-extender data-mining intelligence intelligence-gathering

Last synced: 19 Apr 2025

https://github.com/bit4woo/burp-api-common

common methods that used by my burp extension projects

burp burp-api burp-extensions burp-plugin methods

Last synced: 13 May 2025

https://github.com/JaveleyQAQ/SQL-Injection-Scout

SQL Injection Scout 是一个用于 Burp Suite 的扩展,专为帮助安全研究人员和开发人员检测和分析 SQL 注入漏洞而设计。该扩展提供了丰富的配置选项和直观的用户界面,便于用户自定义扫描和分析过程。

burp burp-extensions burp-plugin burpsuite sqlinject sqlinjection sqlinjectionattack

Last synced: 31 Oct 2025

https://github.com/thekingofduck/copy2java

一键生成Java代码的burp插件/Generate Java script for fuzzing in Burp。

burp-plugin fuzzing java-script-generater

Last synced: 16 Apr 2025

https://github.com/ricardojba/poi-slinger

Automatically identify serialization issues in PHP Frameworks by means of an Burp Suite active scan

burp burp-extensions burp-plugin burpsuite burpsuite-extender burpsuite-pro burpsuitepro

Last synced: 19 Apr 2025

https://github.com/augustd/burp-suite-software-version-checks

Burp extension to passively scan for applications revealing software version numbers

burp burp-extensions burp-plugin burpsuite java penetration-testing pentest scanning

Last synced: 19 Apr 2025

https://github.com/aress31/google-authenticator

Burp Suite plugin that dynamically generates Google 2FA codes for use in session handling rules (approved by PortSwigger for inclusion in their official BApp Store).

burp-plugin burpsuite google java two-factor-authentication

Last synced: 22 Mar 2025

https://github.com/BitTheByte/BitTraversal

Burpsuite Plugin to detect Directory Traversal vulnerabilities

bugbounty burp-extensions burp-plugin burpsuite burpsuite-extender java path-traversal traversal web

Last synced: 11 Jul 2025

https://github.com/cyal1/PyBurp

PyBurp is a Burp Suite extension that provides predefined Python functions for HTTP/WebSocket traffic modification, context menu registration, Intruder payload processing, passive/active scanning, and Collaborator interaction. You can also directly access Montoya API in your Python scripts.

burp-extensions burp-plugin burpsuite-extender decrypt frida grpc nosql-injection passive-vulnerability-scanner

Last synced: 13 May 2025

https://github.com/lwierzbicki/RegexFinder

RegexFinder - Burp Suite extension to passively scan responses for occurrence of regular expression patterns.

burp-extensions burp-plugin burpsuite burpsuite-extender java pentesting scanning

Last synced: 11 Jul 2025

https://github.com/augustd/burp-suite-utils

Utilities for creating Burp Suite Extensions.

burp burp-api burp-extensions burp-plugin burpsuite java

Last synced: 11 Jul 2025

https://github.com/augustd/burp-suite-swaggy

Burp Suite extension for parsing Swagger web service definition files

burp burp-extensions burp-plugin burpsuite java penetration-testing pentest swagger

Last synced: 19 Apr 2025

https://github.com/hvqzao/burp-token-rewrite

Burp extension for automated handling of CSRF tokens

burp burp-extensions burp-plugin burpsuite csrf-tokens

Last synced: 19 Apr 2025

https://github.com/augustd/burp-suite-gwt-scan

Burp Suite plugin identifies insertion points for GWT (Google Web Toolkit) requests

burp burp-extensions burp-plugin burpsuite gwt java penetration-testing pentest

Last synced: 19 Apr 2025

https://github.com/helloexp/burpsuiteplugin

编写 burp suite 插件

burp burp-plugin burpsuite

Last synced: 24 Feb 2025

https://github.com/Ebryx/SRePlay

Burpsuite Plugin to bypass strict RePlay protection

burp burp-extensions burp-plugin burpsuite burpsuite-extender burpsuite-tools

Last synced: 11 Jul 2025

https://github.com/thomashartm/burp-domsink-logger

Injects a trusted types policy into an HTML page to log all DOM sinks whenever HTML is written into the DOM.

burp burp-extensions burp-plugin burpsuite-extender cross-site-scripting domxss java javascript penetration-testing-tools security-testing security-tools trusted-types

Last synced: 23 Mar 2025

https://github.com/aress31/copy-as-powershell-requests

Copy as PowerShell request(s) plugin for Burp Suite (approved by PortSwigger for inclusion in their official BApp Store).

burp-plugin burpsuite clipboard pentesting powershell

Last synced: 12 Apr 2025

https://github.com/ax/burp-logs

Logs is a Burp Suite extension to work with log files.

burp burp-extensions burp-logs burp-plugin burpsuite import log logs parser reader

Last synced: 03 Jul 2025

https://github.com/dradis/burp-dradis

Dradis Framework extension for Burp Suite

burp burp-plugin burpsuite dradis dradis-framework extender

Last synced: 05 Dec 2025

https://github.com/sunny0day/burp-auto-drop

Burp extension to automatically drop requests that match a certain regex.

burp burp-extensions burp-plugin burpsuite

Last synced: 19 Apr 2025

https://github.com/celsogbezerra/Copy-as-JavaScript-Request

Copy as JavaScript Request plugin for Burp Suite

burp-extensions burp-plugin burpsuite java-8 javascript

Last synced: 19 Apr 2025

https://github.com/FY036/BurpGCR

burp的Decoder遇到汉字会出现乱码,此工具用来修复这个乱码

burp-plugin burpsite

Last synced: 07 Sep 2025

https://github.com/b4dpxl/Burp-Timestamp-Editor

Provides a popup menu to edit Unix timestamps in Burp message editors

burp-plugin burpsuite

Last synced: 13 May 2025

https://github.com/33time/captcha-killer-5h6m

原插件在新版本burpsuite无法使用,对插件jdk版本进行升级,引用jdk8、base64包

burp-extensions burp-plugin burpsuite-extender captcha

Last synced: 11 Jul 2025

https://github.com/Redguard/Sheet-Intruder

Enables transparent use of Excel files in Burp Suite

burp-extensions burp-plugin burpsuite excel montoya-api penetration-testing

Last synced: 13 May 2025

https://github.com/Sean-McRae/OAuthv1---Signing-Burp-Extension-

Expands the capabilities of Burp Suite's Platform Authentication by adding additional authentication methods (OAuth v1)

authentication burp-extensions burp-plugin burpsuite oauth oauth1

Last synced: 13 May 2025