Automated blind-xss search for Burp Suite Femida is a tool that helps you find blind XSS vulnerabilities in your web application. It uses Burp Suite as a proxy to intercept and analyze HTTP requests. Femida is a Python script that can be run from the command line. It's a great tool for security researchers and penetration testers who want to automate their blind XSS searches. Femida is open-source and free to use. It's available on GitHub and can be easily installed using pip.
FEATURES
SIMILAR TOOLS
A tool for deep analysis of malicious files using ClamAV and YARA rules, with features like scoring suspect files, building visual tree graphs, and extracting specific patterns.
A collaborative malware analysis framework with various features for automated analysis tasks.
A portable version of XSSHunter.com for finding and exploiting Cross-Site Scripting (XSS) vulnerabilities.
Bindings for the Yara library from VirusTotal with support for Yara v4.2 and various features like rule compilation and scanning.
Command line tool for testing CRLF injection on a list of domains.
Management portal for LoKi scanner with centralized database for scanning activities.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.