Take it like a gift

Aranea
Aranea

OSINT tool used for web crawling or examining JavaScript files for likely useful data.

snallygaster
snallygaster

Tool to scan for secret files on HTTP servers.

google-authenticator-exporter
google-authenticator-exporter

Get the TOTP secrets exported by Google Authenticator.

django-DefectDojo
django-DefectDojo

DevSecOps, ASPM, Vulnerability Management.

dontgo403
dontgo403

Tool to bypass 40X response codes.

additional-scanner-checks
additional-scanner-checks

Collection of scanner checks missing in Burp.

b374k
b374k

PHP Webshell with handy features.

json-web-tokens
json-web-tokens

JSON Web Tokens Support for Burp Suite.

FakeImageExploiter
FakeImageExploiter

Use a Fake image.jpg to exploit targets (hide known file extensions).

hakoriginfinder
hakoriginfinder

Discover the origin host behind a reverse proxy, useful for bypassing cloud WAFs!.

Injectify
Injectify

Perform advanced MiTM attacks on websites with ease.

Betterscan
Betterscan

Code Scanning/SAST/static analysis/linting using many tools/scanners with one report.

Havoc
Havoc

Modern and malleable post-exploitation command and control framework.

bypasswaf
bypasswaf

Add headers to all Burp requests to bypass some WAF products.

Injectus
Injectus

CRLF and open redirect fuzzer.