Burp Extensions Open Source Projects
Browse 63 Burp Extensions open source projects, ranked by GitHub stars. Find the most popular Burp Extensions tools and libraries.
Mr-xn/BurpSuite-collections
有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file
Metrics details
| Stars | 3,942 |
snoopysecurity/awesome-burp-extensions
A curated list of amazingly awesome Burp Extensions
Metrics details
| Stars | 3,426 |
aress31/burpgpt
A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.
Metrics details
| Stars | 2,339 |
API-Security/APIKit
APIKit:Discovery, Scan and Audit APIs Toolkit All In One.
Metrics details
| Stars | 2,281 |
bit4woo/knife
A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅
Metrics details
| Stars | 1,949 |
f0ng/captcha-killer-modified
captcha-killer的修改版,支持关键词识别base64编码的图片,添加免费ocr库,用于验证码爆破,适配新版Burpsuite
Metrics details
| Stars | 1,939 |
sleeyax/burp-awesome-tls
Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.
Metrics details
| Stars | 1,867 |
wagiro/BurpBounty
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
Metrics details
| Stars | 1,809 |
doyensec/inql
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
Metrics details
| Stars | 1,798 |
summitt/Nope-Proxy
TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.
Metrics details
| Stars | 1,663 |
whwlsfb/BurpCrypto
BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件
Metrics details
| Stars | 1,645 |
d3vilbug/HackBar
HackBar plugin for Burpsuite
Metrics details
| Stars | 1,633 |
bit4woo/Fiora
Fiora:漏洞PoC框架Nuclei的图形版。快捷搜索PoC、一键运行Nuclei。即可作为独立程序运行,也可作为burp插件使用。
Metrics details
| Stars | 1,282 |
vaycore/OneScan
OneScan 是一款用于递归目录扫描的 BurpSuite 插件
Metrics details
| Stars | 1,253 |
alphaSeclab/awesome-burp-suite
Awesome Burp Suite Resources. 400+ open source Burp plugins, 400+ posts and videos.
Metrics details
| Stars | 1,037 |
anil-yelken/cyber-security
My cyber security tools
Metrics details
| Stars | 1,000 |
c0ny1/captcha-killer
burp验证码识别接口调用插件
Metrics details
| Stars | 928 |
hisxo/ReconAIzer
A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomains and more!
Metrics details
| Stars | 904 |
f0ng/log4j2burpscanner
CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks
Metrics details
| Stars | 842 |
synacktiv/HopLa
HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite
Metrics details
| Stars | 836 |
bit4woo/reCAPTCHA
reCAPTCHA = REcognize CAPTCHA: A Burp Suite Extender that recognize CAPTCHA and use for intruder payload 自动识别图形验证码并用于burp intruder爆破模块的插件
Metrics details
| Stars | 811 |
c0ny1/sqlmap4burp-plus-plus
sqlmap4burp++是一款兼容Windows,mac,linux多个系统平台的Burp与sqlmap联动插件
Metrics details
| Stars | 798 |
bit4woo/domain_hunter
A Burp Suite Extension that try to find all sub-domain, similar-domain and related-domain of an organization automatically! 基于流量自动收集整个企业或组织的子域名、相似域名、相关域名的burp插件
Metrics details
| Stars | 674 |
Ebryx/AES-Killer
Burp Plugin to decrypt AES encrypted traffic on the fly
Metrics details
| Stars | 652 |
BishopFox/GadgetProbe
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
Metrics details
| Stars | 620 |
Acmesec/Sylas
新一代子域名主/被动收集工具 - Subdomain automatic/passive collection tool
Metrics details
| Stars | 500 |
silentsignal/burp-log4shell
Log4Shell scanner for Burp Suite
Metrics details
| Stars | 485 |
volkandindar/agartha
A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.
Metrics details
| Stars | 401 |
hisxo/JSpector
A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues
Metrics details
| Stars | 381 |
1ultimat3/BadIntent
Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite
Metrics details
| Stars | 323 |
f0ng/autoDecoder-usages
autoDecoder的用法及案例,包含加解密方法、绕waf、替换参数等操作。
Metrics details
| Stars | 315 |
vsec7/BurpSuite-Xkeys
A Burp Suite Extension to extract interesting strings (key, secret, token, or etc.) from a webpage.
Metrics details
| Stars | 314 |
prakharathreya/Struts2-RCE
A Burp Extender for checking for struts 2 RCE vulnerabilities.
Metrics details
| Stars | 285 |
usdAG/cstc
CSTC is a Burp Suite extension that allows request/response modification using a GUI analogous to CyberChef
Metrics details
| Stars | 260 |
nxenon/grpc-pentest-suite
gRPC-Web Pentesting Suite + Burp Suite Extension / Hack gRPC-Web Applications (Official BApp Extension Available)
Metrics details
| Stars | 258 |
c0ny1/HTTPHeadModifer
一款快速修改HTTP数据包头的Burp Suite插件
Metrics details
| Stars | 255 |
bit4woo/u2c
Unicode To Chinese -- U2C : A burpsuite Extender That Convert Unicode To Chinese 【Unicode编码转中文的burp插件】
Metrics details
| Stars | 253 |
d3mondev/burp-vps-proxy
This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.
Metrics details
| Stars | 247 |
NetsOSS/headless-burp
Automate security tests using Burp Suite.
Metrics details
| Stars | 235 |
P3GLEG/PwnBack
Burp Extender plugin that generates a sitemap of a website using Wayback Machine
Metrics details
| Stars | 228 |
simioni87/auth_analyzer
Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.
Metrics details
| Stars | 223 |
Anof-cyber/PyCript
Burp Suite extension to decrypt/encrypt any encrypted traffic (AES/RSA/Encodings and more) with custom code in any language
Metrics details
| Stars | 220 |
aress31/openapi-parser
Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their official BApp Store).
Metrics details
| Stars | 209 |
codingo/Minesweeper
A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).
Metrics details
| Stars | 203 |
silentsignal/burp-text4shell
Text4Shell scanner for Burp Suite
Metrics details
| Stars | 190 |
mwielgoszewski/jython-burp-api
Develop Burp extensions in Jython
Metrics details
| Stars | 180 |
artssec/burp-exporter
Exporter is a Burp Suite extension to copy a request to a file or the clipboard as multiple programming languages functions.
Metrics details
| Stars | 178 |
usdAG/FlowMate
FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application and matches their occurrences in the responses.
Metrics details
| Stars | 169 |
arvinddoraiswamy/mywebappscripts
A collection of all the lists, scripts and techniques I use while doing web application penetration tests.
Metrics details
| Stars | 168 |
moeinfatehi/Backup-Finder
A burp suite extension that reviews backup, old, temporary and unreferenced files on web server for sensitive information (OWASP WSTG-CONF-04, OTG-CONFIG-004)
Metrics details
| Stars | 166 |
xer0days/SQLi-Query-Tampering
SQLi Query Tampering extends and adds custom Payload Generator/Processor in Burp Suite's Intruder. This extension gives you the flexibility of manual testing with many powerful evasion techniques.
Metrics details
| Stars | 157 |
kapytein/jsonp
jsonp is a Burp Extension which attempts to reveal JSONP functionality behind JSON endpoints.
Metrics details
| Stars | 156 |
yandex/burp-molly-scanner
Turn your Burp suite into headless active web application vulnerability scanner
Metrics details
| Stars | 155 |
xer0times/BugBounty
Bug Bounty stuffs, payloads, scripts, profiles, tips and tricks, ...
Metrics details
| Stars | 147 |
Anof-cyber/ParaForge
A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing
Metrics details
| Stars | 142 |
yandex/burp-molly-pack
Security checks pack for Burp Suite
Metrics details
| Stars | 140 |
hvqzao/burp-wildcard
Burp extension intended to compact Burp extension tabs by hijacking them to own tab.
Metrics details
| Stars | 131 |
silentsignal/burp-piper
Piper Burp Suite Extender plugin
Metrics details
| Stars | 130 |
BitTheByte/BitBlinder
BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS vulnerabilities
Metrics details
| Stars | 124 |
moeinfatehi/Admin-Panel_Finder
A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)
Metrics details
| Stars | 122 |
