Skip to content
#

security-testing

Here are 52 public repositories matching this topic...

A Burp Suite extension that puts an LLM-driven vulnerability scan behind a right-click — or behind Proxy auto-scan (off by default), which turns parameterised proxy traffic into scan tasks. The model picks which parameters to attack and with what payloads; the payloads are really sent, and exploitability is decided from the evidence.

  • Updated Sep 27, 2026
  • Java

Application security best practices and code implementations for Java developers. This project is intended for didactic purposes only, supporting my training course.

  • Updated Dec 29, 2025
  • Java
RequestRecorder

A ZAPROXY Add-on that allows testing of web application vulnerabilities by recording complex multi-step sequences. You can test applications that need to access pages in a specific order, such as shopping carts or registration of member information.

  • Updated May 14, 2025
  • Java

🎯 VISTA — AI-Powered Security Testing Assistant for Burp Suite. Real-time traffic analysis, 12 expert vulnerability templates, 80+ payloads, WAF detection & bypass. Supports OpenAI, Azure, and OpenRouter (FREE). Zero dependencies.

  • Updated May 27, 2026
  • Java

Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traffic by listener port (PwnFox-style) — built for Android/iOS multi-account IDOR/BOLA testing, with Magic Cookie, Match & Replace, and .http export for Claude Code / AI.

  • Updated Aug 14, 2026
  • Java

🛡️ Burp Suite extension for automated access control bypass, path traversal & Web Cache Deception testing. Header spoofing, URL encoding, cache deception pipelines – all in one tool.

  • Updated Aug 6, 2026
  • Java

🆓 Free Burp Collaborator Alternative - Advanced Out-of-Band testing for Burp Suite Community & Pro. Multi-bin management, RequestBin.net integration, persistent storage.

  • Updated Mar 28, 2026
  • Java

Burp Suite extension for passive GraphQL reconnaissance. Catalogs operations from proxy traffic, tracks variable shapes with sample values, stores original requests per signature, and sends to Intruder with auto-marked payload positions. Supports status triage, export/import for session persistence, and batched mutation detection.

  • Updated Mar 16, 2026
  • Java

Add this topic to your repo

To associate your repository with the security-testing topic, visit your repo's landing page and select "manage topics."

Learn more