A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI
-
Updated
Sep 22, 2026 - Kotlin
A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI
This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.
Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.
BurpSuite Extension leveraging new Montoya API to automatically sets payload positions to your inruder tab saving you time during VAPT.
This extension integrates popular CAPTCHA solution services into BurpSuite to process different types of CAPTCHAs without manual intervention.
Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traffic by listener port (PwnFox-style) — built for Android/iOS multi-account IDOR/BOLA testing, with Magic Cookie, Match & Replace, and .http export for Claude Code / AI.
Autonomous AI penetration testing agent for Burp Suite. Agentic pentesting with local/cloud LLMs (Ollama, Gemini, DeepSeek, OpenRouter) via Montoya API.
REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.
🛡️ Burp Suite extension for automated access control bypass, path traversal & Web Cache Deception testing. Header spoofing, URL encoding, cache deception pipelines – all in one tool.
Enables transparent use of Excel files in Burp Suite
Burp Suite extension implementing OWASP API Security Top 10 (2023) coverage on the Montoya API — active + passive scan checks with optional Burp AI integration
Proof-of-testing coverage tracker for Burp Suite — automatically captures traffic from all tools, classifies testing depth per endpoint, and highlights untested gaps in your scope.
OWASP Sentinel Pro - real-time passive OWASP Top 10 + JWT/OAuth/SAML scanner for Burp Suite (Montoya API)
Defensive, local Burp Suite extension mapping existing findings to CWE, OWASP Web/API/Mobile/MASVS/ASVS/GenAI, MITRE ATT&CK/D3FEND/ATLAS/AADAPT/F3 and CVSS 4.0, with explainable confidence and local JSON/CSV/Markdown/SARIF exports.
Burp Suite Pro extension (Montoya API): HTTP request-smuggling / desync hypothesis scanner with a framing-aware, oracle-free classifier and Burp Collaborator OOB (SSRF) detection.
Burp Suite extension: automated IDOR detection via three-way response comparison
This BurpSuite extension tests ESPv2 malicious X-HTTP-Method-Override header value to bypass JWT authentication in specific cases.
Burp Suite extension that turns a request or response into a clean, report-ready PoC screenshot: hides browser noise headers, blurs secrets, removes lines. Repeater, Logger and Proxy.
Burp Suite Professional extension with embedded Discord bot for real-time scan control, findings notifications, and workflow automation
This Burp Suite extension monitors a provided JWT token for its expiration and replaces any already present JWT token in outgoing requests with the provided one
To associate your repository with the montoya-api topic, visit your repo's landing page and select "manage topics."