Take it like a gift

BaRMIe
BaRMIe

Enumerating and attacking Java Remote Method Invocation services.

magspoof
magspoof

A portable device that can spoof/emulate any magnetic stripe, credit card or hotel card wirelessly.

json-web-tokens
json-web-tokens

JSON Web Tokens Support for Burp Suite.

Femida
Femida

Automated blind-xss search for Burp Suite.

dvcs-ripper
dvcs-ripper

Rip web accessible version control systems: svn, git...

amap
amap

Identify applications even if they are running on a different port than normal.

Feroxbuster
Feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

gef
gef

A modern experience for GDB with advanced debugging capabilities.

FavFreak
FavFreak

Making favicon.ico based recon great again.

Argus-SAF
Argus-SAF

Static analysis framework built in house to do security vetting for Android applications.

FestIN
FestIN

The powered S3 bucket finder and content discover.

FireBounty
FireBounty

The ultimate Vulnerability Disclosure Policy and Bug Bounty list!

attack_range
attack_range

Create vulnerable instrumented local or cloud environments to simulate attacks.

DVCA
DVCA

Damn vulnerable cloud application.

Flow
Flow

Provides view with filtering capabilities for all requests from all Burp Suite tools.