Take it like a gift

s3cXSSer
s3cXSSer

This extension will help you to detect GET/POST based XSS vulnerability in any website easily.

B-XSSRF
B-XSSRF

Toolkit to detect and keep track on Blind XSS, XXE & SSRF.

IAMagic
IAMagic

Advanced AWS access credentials scanner.

Apidor
Apidor

Tool for automating the search for IDOR vulnerabilities in web applications and APIs.

bountyplz
bountyplz

Automated security reporting from markdown templates.

ACLight
ACLight

Advanced discovery of Privileged Accounts, includes Shadow Admins.

Altdns
Altdns

Generates permutations, alterations and mutations of subdomains and then resolves them.

ADRecon
ADRecon

Gather information about the Active Directory and generates a report.

Gopherus
Gopherus

Generates gopher link for exploiting SSRF and gaining RCE in various servers.

AWS security checks
AWS security checks

This Burp Suite provides additional Scanner checks for AWS security issues.

ffufPostprocessing
ffufPostprocessing

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

angr
angr

A powerful and user-friendly binary analysis platform.

AzureADLateralMovement
AzureADLateralMovement

Lateral movement graph for Azure Active Directory.

Evilginx3
Evilginx3

Standalone MITM attack framework allowing for the bypass of 2-factor authentication.

androguard
androguard

Reverse engineering and pentesting for Android applications.