SecHub provides a central API to test software with different security tools.
-
Updated
Jan 12, 2026 - Java
SecHub provides a central API to test software with different security tools.
A Cloud Security Posture Manager or CSPM with a focus on security analysis for the modern cloud stack and a focus on the emerging threat landscape such as cloud ransomware and supply chain attacks.
A Burp Suite extension that puts an LLM-driven vulnerability scan behind a right-click — or behind Proxy auto-scan (off by default), which turns parameterised proxy traffic into scan tasks. The model picks which parameters to attack and with what payloads; the payloads are really sent, and exploitability is decided from the evidence.
PROJECT DELTA: SDN SECURITY EVALUATION FRAMEWORK
Application security best practices and code implementations for Java developers. This project is intended for didactic purposes only, supporting my training course.
Integrated Security Testing Environment for Web Applications as Burp Extension.
Safelog4j is an instrumentation-based security tool to help teams discover, verify, and solve log4shell vulnerabilities without scanning or upgrading
A ZAPROXY Add-on that allows testing of web application vulnerabilities by recording complex multi-step sequences. You can test applications that need to access pages in a specific order, such as shopping carts or registration of member information.
🎯 VISTA — AI-Powered Security Testing Assistant for Burp Suite. Real-time traffic analysis, 12 expert vulnerability templates, 80+ payloads, WAF detection & bypass. Supports OpenAI, Azure, and OpenRouter (FREE). Zero dependencies.
This extension integrates popular CAPTCHA solution services into BurpSuite to process different types of CAPTCHAs without manual intervention.
Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traffic by listener port (PwnFox-style) — built for Android/iOS multi-account IDOR/BOLA testing, with Magic Cookie, Match & Replace, and .http export for Claude Code / AI.
Injects a trusted types policy into an HTML page to log all DOM sinks whenever HTML is written into the DOM.
Mapping ISO 27001 to Modern Software Engineering: Secure by Design
Web-Browser like Java app to send raw HTTP requests, it is designed for debugging and finding security issues in web applications.
A prototype of an Interactive Application Security Testing System
🛡️ Burp Suite extension for automated access control bypass, path traversal & Web Cache Deception testing. Header spoofing, URL encoding, cache deception pipelines – all in one tool.
🆓 Free Burp Collaborator Alternative - Advanced Out-of-Band testing for Burp Suite Community & Pro. Multi-bin management, RequestBin.net integration, persistent storage.
Integrate our security scans with your Jenkins CI/CD pipeline
Burp Suite extension for passive GraphQL reconnaissance. Catalogs operations from proxy traffic, tracks variable shapes with sample values, stores original requests per signature, and sends to Intruder with auto-marked payload positions. Supports status triage, export/import for session persistence, and batched mutation detection.
ParamFinder
To associate your repository with the security-testing topic, visit your repo's landing page and select "manage topics."