Take it like a gift
hakfindinternaldomains
Feed it a list of subdomains, it will resolve them and tell you which ones are internal.
FlowMate
A Burp Suite extension that brings taint analysis to web applications, by tracking all parameters.
XSS Hunter
The fastest way to set up XSS Hunter to test and find blind cross-site scripting vulnerabilities.
FuzzDB
Attack patterns and primitives for black-box application fault injection and resource discovery.
Burp-Encode-IP
Burp Suite extension to encode an IP address focused to bypass application IP/domain blacklist.