This is a Burp plugin that extracts keywords from response using regexes and tests for reflected XSS on the target scope. It can be used to identify potential vulnerabilities in web applications and to help security researchers and developers to identify and fix security issues. The plugin is designed to be easy to use and to provide a high level of accuracy in identifying potential vulnerabilities. It is available for free and can be downloaded from the GitHub repository.
FEATURES
SIMILAR TOOLS
YARA rules for ProcFilter to detect malware and threats
A strings statistics calculator for YARA rules to aid malware research.
Use FindYara, an IDA python plugin, to scan your binary with yara rules and quickly jump to matches.
Exploiting a vulnerability in HID iClass system to retrieve master authentication key for cloning cards and changing reader settings.
Command line tool for testing CRLF injection on a list of domains.
RetDec is a versatile machine-code decompiler with support for various file formats and architectures.
Collection of Python scripts for automating tasks and enhancing IDA Pro functionality
A tool for translating Dalvik bytecode to Java bytecode for analyzing Android applications.
KLara is a distributed system written in Python that helps Threat Intelligence researchers hunt for new malware using Yara.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.