awesome-burp-extensions
github.com/snoopysecurity/awesome-burp-extensions ↗A curated list of amazingly awesome Burp Extensions
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me cross-site request forgery resources from awesome-burp-extensions"
Installation instructions →What's inside
Web Application Firewall Evasion
- 403Bypasser
A Burp Suite extension made to automate the process of bypassing 403 pages.
- Awesome TLS
This extension overrides Burp Suite's default HTTP and TLS stack to make it immune to WAF fingerprinting methods such as JA3, HTTP2 frames, etc.
- BurpSuiteHTTPSmuggler
A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques.
- Burp Suite HTTP Smuggler
A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques.
- Bypass WAF
Add headers to all Burp requests to bypass some WAF products.
- Chunked coding converter
This entension use a Transfer-Encoding technology to bypass the waf.
Resources
- 403Bypasser
An burpsuite extension to bypass 403 restricted directory.
- Active Scan++
ActiveScan++ extends Burp Suite's active and passive scanning capabilities.
- ActiveScan3Plus
Modified version of ActiveScan++ Burp Suite extension.
- Additional Scanner checks
Collection of scanner checks missing in Burp.
- Backslash Powered Scanner
Finds unknown classes of injection vulnerabilities.
- blinks
Blinks is a powerful Burp Suite extension that automates active scanning with Burp Suite Pro and enhances its functionality. With the integration of webhooks, this tool sends real-time updates whenever a new issue is identified, directly to your preferred endpoint.
Web Services
- 5GC_API_parse
5GC API parse is a BurpSuite extension allowing to assess 5G core network functions, by parsing the OpenAPI 3.0 not supported by previous OpenAPI extension in Burp, and generating requests for intrusion tests purposes.
- Burp Non HTTP Extension
Non-HTTP Protocol Extension (NoPE) Proxy and DNS for Burp Suite.
- burp-suite-swaggy
Burp Suite extension for parsing Swagger web service definition files.
- BurpWCFDSer
BurpWCFDSer is a Burp plugin that will deserialze/serialize WCF request and response to and from XML.
- Burp WS-Security
This extension calculate a valid WS security token for every request (In Proxy, Scanner, Intruder, Repeater, Sequencer, Extender), and replace variables in theses requests by the valid token.
- Content Type Converter
Burp extension to convert XML to JSON, JSON to XML, x-www-form-urlencoded to XML, and x-www-form-urlencoded to JSON.
Misc
- Add Custom Header
A Burp Suite extension to add a custom header (e.g. JWT).
- Asset Saver - Burp Suite
Burp Suite extension for saving previously loaded assets .
- Autowasp
a Burp Suite extension that integrates Burp issues logging, with OWASP Web Security Testing Guide (WSTG), to provide a streamlined web security testing flow for the modern-day penetration tester
- Batch Scan Report Generator
This extension can be used to generate multiple scan reports by host with just a few clicks.
- BCheck Helper
BCheck Helper makes finding and importing BChecks scripts into Burp easier by loading them from either a remote GitHub or local Git repository.
- BlockerLite
Simple Burp extension to drop blacklisted hosts.
Vulnerability Specific Extensions
- Additional CSRF Checks/EasyCSRFCross-Site Request Forgery
EasyCSRF helps to find weak CSRF-protection in WebApp which can be easily bypassed.
- Add Request to MacroSession Management
This Burp extension lets you add a request to an existing macro.
- AdminPanelFinderBroken Access Control
A burp suite extension that enumerates infrastructure and application Admin Interfaces (OWASP OTG-CONFIG-005)
- Anti-CSRF Token From RefererCross-Site Request Forgery
The extension works by registering a new session handling rule called "Anti-CSRF token from referer".
- Argument Injection HammerCommand Injection
it is used to identify argument injection vulnerabilities, like
- Auth AnalyzerBroken Access Control
This Burp Extension helps you to find authorization bugs by repeating Proxy requests with self defined headers and tokens.
Information Gathering
- Add to sitemap++
Add to sitemap++ is a BURP extension that can read URLs from files or clipboard and add the discovered information on the site map of the selected host(s).
- Asset Discover
Burp Suite extension to discover assets from HTTP response using passive scanning.
- Attack Surface Detector
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters.
- BigIP Discover
A extension of Burp suite. The cookie set by the BipIP server may include a private IP, which is an extension to detect that IP
- Burp CSJ
This extension integrates Crawljax, Selenium and JUnit together. The intent of this extension is to aid web application security testing, increase web application crawling capability and speed-up complex test-cases execution.
Cryptography
- Add To TLS Pass Through Extension
Burp Extension to add context menus for configuration of the Add to TLS Pass Through setting
- AES Burp/AES Payloads
Burp Extension to manipulate AES encrypted payloads.
- AES Killer
Burp plugin to decrypt AES Encrypted traffic of mobile apps on the fly.
- BurpCrypto
Burpcrypto is a collection of burpsuite encryption plug-ins, supporting AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite).
Custom Features
- Add & Track Custom Issues
This extension allows custom scan issues to be added and tracked within Burp.
- Add & Track Custom Issues
This extension allows custom scan issues to be added and tracked within Burp.
- Attack Surface Detector
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters.
- Auto Drop
This extension allows you to automatically Drop requests that match a certain regex. Helpful in case the target has logging or tracking services enabled.
- Backup Finder
A burp suite extension that reviews backup, old, temporary, and unreferenced files on the webserver for sensitive information.
- BadIntent
Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite.
Showing a sample of 499 resources. View the full list on GitHub →