OSINT tool used for web crawling or examining JavaScript files for likely useful data.
Tool to scan for secret files on HTTP servers.
Get the TOTP secrets exported by Google Authenticator.
DevSecOps, ASPM, Vulnerability Management.
Tool to bypass 40X response codes.
Collection of scanner checks missing in Burp.
PHP Webshell with handy features.
JSON Web Tokens Support for Burp Suite.
Use a Fake image.jpg to exploit targets (hide known file extensions).
Discover the origin host behind a reverse proxy, useful for bypassing cloud WAFs!.
Perform advanced MiTM attacks on websites with ease.
Code Scanning/SAST/static analysis/linting using many tools/scanners with one report.
Modern and malleable post-exploitation command and control framework.
Add headers to all Burp requests to bypass some WAF products.
CRLF and open redirect fuzzer.