Skip to main content

A curated list of amazingly awesome Burp Extensions

3.4k
GitHub Stars
499
Curated Resources
15
Categories
1 hour ago
Last Refreshed
Custom FeaturesBeautifiers and DecodersCloud SecurityScriptingOAuth and SSOInformation GatheringVulnerability Specific ExtensionsWeb Application Firewall EvasionLogging and NotesPayload Generators and FuzzersCryptographyWeb ServicesTool IntegrationMiscBurp Extension Training Resources

Use this list with your AI agent

Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:

"Show me cross-site request forgery resources from awesome-burp-extensions"

Installation instructions →

What's inside

Web Application Firewall Evasion

  • 403Bypasser

    A Burp Suite extension made to automate the process of bypassing 403 pages.

  • Awesome TLS

    This extension overrides Burp Suite's default HTTP and TLS stack to make it immune to WAF fingerprinting methods such as JA3, HTTP2 frames, etc.

  • BurpSuiteHTTPSmuggler

    A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques.

  • Burp Suite HTTP Smuggler

    A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques.

  • Bypass WAF

    Add headers to all Burp requests to bypass some WAF products.

  • Chunked coding converter

    This entension use a Transfer-Encoding technology to bypass the waf.

Resources

  • 403Bypasser

    An burpsuite extension to bypass 403 restricted directory.

  • Active Scan++

    ActiveScan++ extends Burp Suite's active and passive scanning capabilities.

  • ActiveScan3Plus

    Modified version of ActiveScan++ Burp Suite extension.

  • Additional Scanner checks

    Collection of scanner checks missing in Burp.

  • Backslash Powered Scanner

    Finds unknown classes of injection vulnerabilities.

  • blinks

    Blinks is a powerful Burp Suite extension that automates active scanning with Burp Suite Pro and enhances its functionality. With the integration of webhooks, this tool sends real-time updates whenever a new issue is identified, directly to your preferred endpoint.

Web Services

  • 5GC_API_parse

    5GC API parse is a BurpSuite extension allowing to assess 5G core network functions, by parsing the OpenAPI 3.0 not supported by previous OpenAPI extension in Burp, and generating requests for intrusion tests purposes.

  • Burp Non HTTP Extension

    Non-HTTP Protocol Extension (NoPE) Proxy and DNS for Burp Suite.

  • burp-suite-swaggy

    Burp Suite extension for parsing Swagger web service definition files.

  • BurpWCFDSer

    BurpWCFDSer is a Burp plugin that will deserialze/serialize WCF request and response to and from XML.

  • Burp WS-Security

    This extension calculate a valid WS security token for every request (In Proxy, Scanner, Intruder, Repeater, Sequencer, Extender), and replace variables in theses requests by the valid token.

  • Content Type Converter

    Burp extension to convert XML to JSON, JSON to XML, x-www-form-urlencoded to XML, and x-www-form-urlencoded to JSON.

Misc

  • Add Custom Header

    A Burp Suite extension to add a custom header (e.g. JWT).

  • Asset Saver - Burp Suite

    Burp Suite extension for saving previously loaded assets .

  • Autowasp

    a Burp Suite extension that integrates Burp issues logging, with OWASP Web Security Testing Guide (WSTG), to provide a streamlined web security testing flow for the modern-day penetration tester

  • Batch Scan Report Generator

    This extension can be used to generate multiple scan reports by host with just a few clicks.

  • BCheck Helper

    BCheck Helper makes finding and importing BChecks scripts into Burp easier by loading them from either a remote GitHub or local Git repository.

  • BlockerLite

    Simple Burp extension to drop blacklisted hosts.

Vulnerability Specific Extensions

  • Additional CSRF Checks/EasyCSRFCross-Site Request Forgery

    EasyCSRF helps to find weak CSRF-protection in WebApp which can be easily bypassed.

  • Add Request to MacroSession Management

    This Burp extension lets you add a request to an existing macro.

  • AdminPanelFinderBroken Access Control

    A burp suite extension that enumerates infrastructure and application Admin Interfaces (OWASP OTG-CONFIG-005)

  • Anti-CSRF Token From RefererCross-Site Request Forgery

    The extension works by registering a new session handling rule called "Anti-CSRF token from referer".

  • Argument Injection HammerCommand Injection

    it is used to identify argument injection vulnerabilities, like

  • Auth AnalyzerBroken Access Control

    This Burp Extension helps you to find authorization bugs by repeating Proxy requests with self defined headers and tokens.

Information Gathering

  • Add to sitemap++

    Add to sitemap++ is a BURP extension that can read URLs from files or clipboard and add the discovered information on the site map of the selected host(s).

  • Asset Discover

    Burp Suite extension to discover assets from HTTP response using passive scanning.

  • Attack Surface Detector

    The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters.

  • BigIP Discover

    A extension of Burp suite. The cookie set by the BipIP server may include a private IP, which is an extension to detect that IP

  • Burp CSJ

    This extension integrates Crawljax, Selenium and JUnit together. The intent of this extension is to aid web application security testing, increase web application crawling capability and speed-up complex test-cases execution.

Cryptography

  • Add To TLS Pass Through Extension

    Burp Extension to add context menus for configuration of the Add to TLS Pass Through setting

  • AES Burp/AES Payloads

    Burp Extension to manipulate AES encrypted payloads.

  • AES Killer

    Burp plugin to decrypt AES Encrypted traffic of mobile apps on the fly.

  • BurpCrypto

    Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).

Custom Features

  • Add & Track Custom Issues

    This extension allows custom scan issues to be added and tracked within Burp.

  • Add & Track Custom Issues

    This extension allows custom scan issues to be added and tracked within Burp.

  • Attack Surface Detector

    The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters.

  • Auto Drop

    This extension allows you to automatically Drop requests that match a certain regex. Helpful in case the target has logging or tracking services enabled.

  • Backup Finder

    A burp suite extension that reviews backup, old, temporary, and unreferenced files on the webserver for sensitive information.

  • BadIntent

    Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite.

Showing a sample of 499 resources. View the full list on GitHub →