武装 Burp

  1. Fiora

    演示:Weblogic(Vulhub)

    Nuclei 提供 Poc 图形界面,实现快速搜索、一键运行等功能,提升体验。

    https://github.com/bit4woo/Fiora

    https://github.com/perlh/Wavely

  2. TsojanScan

    演示:Weblogic(Vulhub)

    集成的 BurpSuite 常见漏洞探测插件

    https://github.com/Tsojan/TsojanScan

  3. RouteVulScan

    演示:Weblogic(Vulhub)

    递归式被动检测脆弱路径的 burp 插件

    https://github.com/F6JO/RouteVulScan

  4. GatherBurp

    演示http://testphp.vulnweb.com/

    https://github.com/kN6jq/gatherBurp

  5. 奇安信明动

    演示:Log4j (Vulfocus)

  6. 辅助分析类

    演示:BurpFingerPrint

    https://github.com/gh0stkey/HaE

    https://github.com/bit4woo/knife

    https://github.com/shuanx/BurpFingerPrint

    https://github.com/yxdm02/EnhancedBurpGPT

    https://github.com/bit4woo/domain_hunter_pro


武装浏览器

演示

SnowEyes

BucketTool

PolarisScan

FindSomething

https://github.com/SickleSec/SnowEyes

https://github.com/libaibaia/BucketTool

https://github.com/LinBeiPolaris/PolarisScan

https://github.com/momosecurity/FindSomething

其他

  • HackBar
  • Wappalyzer
  • Hack-Tools
  • Save-Multiple-URLs
  • Penetration Testing Kit