burp-plugin topic
openapi-parser
Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their official BApp Store).
auth_analyzer
Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.
mssqli-duet
SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing
burp-suite-error-message-checks
Burp Suite extension to passively scan for applications revealing server error messages
burp-shell-fwd-lfi
A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration
burp-sensitive-param-extractor
burpsuite extension for check and extract sensitive request parameter
burp-info-extractor
burpsuite extension for extract information from data
burp-aem-scanner
Burp Scanner extension to fingerprint and actively scan instances of the Adobe Experience Manager CMS. It checks the website for common misconfigurations and security holes.
BitBlinder
BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS vulnerabilities
lazyCSRF
A more useful CSRF PoC generator on Burp Suite