turbo-intruder

Attack simulator

A tool for sending and analyzing large numbers of HTTP requests to test web application security vulnerabilities.

Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.

GitHub

2k stars
35 watching
217 forks
Language: Kotlin
last commit: about 2 months ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

Repository Description Stars
portswigger/backslash-powered-scanner An extension for Burp Suite that scans for unknown classes of injection vulnerabilities using a novel approach 643
portswigger/json-decoder A set of BurpSuite extensions for pentesting and testing 10
portswigger/command-injection-attacker An OS command injection detection and exploitation tool that provides methodologies and software for identifying and exploiting vulnerabilities in applications. 106
portswigger/http-request-smuggler An extension for Burp Suite to help identify and exploit HTTP Request Smuggling vulnerabilities. 964
portswigger/httpoxy-scanner Tools to help identify vulnerabilities in web applications using HTTPoxy scanning. 90
portswigger/additional-scanner-checks A collection of passive scanner checks to identify security vulnerabilities in web applications 27
portswigger/html5-auditor An HTML validation and security testing tool for identifying vulnerabilities in web applications 4
volkandindar/agartha An extension for a web application security testing tool that identifies vulnerabilities and exploits HTTP requests for penetration testing. 355
portswigger/crypto-attacker A collection of tools and scripts for penetration testing and vulnerability assessment of web applications. 2
1n3/intruderpayloads A collection of tools and methodologies for identifying vulnerabilities in web applications 3,698
uber-common/metta An adversarial simulation tool to test information security preparedness by simulating network-based attacks on various systems. 1,103
portswigger/active-scan-plus-plus An extension to Burp Suite's scanning capabilities designed to identify application behavior of interest to advanced testers. 209
elastic/swat A tool designed to simulate malicious behavior against Google Workspace environments for threat research and detection rule effectiveness testing 163
portswigger/param-miner An extension tool used to identify hidden parameters in web requests 1,273
portswigger/reflected-parameters Tools and techniques for exploiting reflected parameter vulnerabilities in Java-based applications 19