AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
-
Updated
Jul 4, 2026 - Java
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
Pentest Coverage Tracker is a Burp Suite extension that helps penetration testers monitor testing coverage in real time. It logs discovered endpoints and tracks whether their parameters are actually tested in Burp Suite. This helps highlight untested attack surfaces and provides clear visibility of coverage for security teams.
A passive recursive path probing extension for Burp Suite, built on the Montoya API with YAML rules and low-noise vulnerability detection.
Lightweight BApp that seamlessly integrates powerful LLM-scanning capabilities into Burp's built-in Scanner with improved accuracy. Supports the latest LLMs from OpenAI (gpt-4o, o1), Anthropic (Claude 3.5, Claude 3), and Google (Gemini 1.5). Requires valid API key(s) and an active Burp Suite Pro or Enterprise license.
BurpSuite 被动指纹识别 / Favicon Hash / 递归目录扫描 / 路径收集 一体化插件
Burpsuite extension. Supports CJK (Chinese, Japanese, Korean) encoding.
Burp Suite extension for passive JS reconnaissance - detects 1,600+ secret patterns, API keys, endpoints, and security misconfigurations in HTTP responses in real-time.
🎯 VISTA — AI-Powered Security Testing Assistant for Burp Suite. Real-time traffic analysis, 12 expert vulnerability templates, 80+ payloads, WAF detection & bypass. Supports OpenAI, Azure, and OpenRouter (FREE). Zero dependencies.
Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traffic by listener port (PwnFox-style) — built for Android/iOS multi-account IDOR/BOLA testing, with Magic Cookie, Match & Replace, and .http export for Claude Code / AI.
A Burp extension for finding AWS secrets
✨ is a Burp Suite extension that gives every Repeater tab a meaningful name - automatically, the moment the request arrives.
Burp Suite 自动注入 X-Forwarded-For、X-Real-IP 等 HTTP Header 插件,用于 IP 伪造、WAF 绕过、CDN 回源
MCP wrapper for Burp Suite that builds complete, well-formed HTTP requests from structured input + ingests dedup/JS exports for token-thrifty AI-assisted pentesting. Bundles a fixed Burp extension.
🆓 Free Burp Collaborator Alternative - Advanced Out-of-Band testing for Burp Suite Community & Pro. Multi-bin management, RequestBin.net integration, persistent storage.
Stop manually replacing cookies in every Repeater tab. Define your session tokens once and Cookie Swapper auto-applies them to any request. Perfect for retesting bugs with fresh cookies across large request histories.
Enhanced Burp Suite MCP Server — Streamable HTTP solves AI disconnection; SQLite cache prevents Burp freezing under load.Burp Suite MCP Server 增强版 — Streamable HTTP 彻底解决AI断连,SQLite 缓存解耦防止Burp卡死
🛡️ Burp Suite extension for automated access control bypass, path traversal & Web Cache Deception testing. Header spoofing, URL encoding, cache deception pipelines – all in one tool.
AI-Powered Burp Suite extension for elite bug bounty hunting. Detects HIGH/CRITICAL vulnerabilities using LLMs.
Burp Suite extension for passive GraphQL reconnaissance. Catalogs operations from proxy traffic, tracks variable shapes with sample values, stores original requests per signature, and sends to Intruder with auto-marked payload positions. Supports status triage, export/import for session persistence, and batched mutation detection.
HarQL - Advanced GraphQL Harvester Burp Suite Extension | No Introspection | Meta FB,IG,.. Optimized | Send to Repeater + Inferred Schema + Pitchfork Export
To associate your repository with the burp-extension topic, visit your repo's landing page and select "manage topics."