This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.
-
Updated
Jul 21, 2026 - Java
This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.
Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.
BurpSuite Extension leveraging new Montoya API to automatically sets payload positions to your inruder tab saving you time during VAPT.
This extension integrates popular CAPTCHA solution services into BurpSuite to process different types of CAPTCHAs without manual intervention.
All-in-one Burp Suite attack framework — 16 active scanners, 4 passive analyzers, SQL exploitation engine (OmniMap), AI-powered fuzzing, prerequisite chain automation (Stepper), built-in OOB server (HTTP+DNS). Single JAR, Montoya API.
Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traffic by listener port (PwnFox-style) — built for Android/iOS multi-account IDOR/BOLA testing, with Magic Cookie, Match & Replace, and .http export for Claude Code / AI.
REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.
Autonomous AI penetration testing agent for Burp Suite. Agentic pentesting with local/cloud LLMs (Ollama, Gemini, DeepSeek, OpenRouter) via Montoya API.
🛡️ Burp Suite extension for automated access control bypass, path traversal & Web Cache Deception testing. Header spoofing, URL encoding, cache deception pipelines – all in one tool.
Enables transparent use of Excel files in Burp Suite
Proof-of-testing coverage tracker for Burp Suite — automatically captures traffic from all tools, classifies testing depth per endpoint, and highlights untested gaps in your scope.
Burp Suite extension implementing OWASP API Security Top 10 (2023) coverage on the Montoya API — active + passive scan checks with optional Burp AI integration
OWASP Sentinel Pro - real-time passive OWASP Top 10 + JWT/OAuth/SAML scanner for Burp Suite (Montoya API)
Defensive, local Burp Suite extension mapping existing findings to CWE, OWASP Web/API/Mobile/MASVS/ASVS/GenAI, MITRE ATT&CK/D3FEND/ATLAS/AADAPT/F3 and CVSS 4.0, with explainable confidence and local JSON/CSV/Markdown/SARIF exports.
This BurpSuite extension tests ESPv2 malicious X-HTTP-Method-Override header value to bypass JWT authentication in specific cases.
This Burp Suite extension monitors a provided JWT token for its expiration and replaces any already present JWT token in outgoing requests with the provided one
Burp Suite Pro extension (Montoya API): HTTP request-smuggling / desync hypothesis scanner with a framing-aware, oracle-free classifier and Burp Collaborator OOB (SSRF) detection.
Burp Suite Professional extension with embedded Discord bot for real-time scan control, findings notifications, and workflow automation
State-aware Burp Suite extension for mutating multi-step workflows and detecting business-logic flaws with probes, invariants, isolated actors, and cleanup.
Burp Suite extension for HTTP verb tampering testing using Montoya API.
Add a description, image, and links to the montoya-api topic page so that developers can more easily learn about it.
To associate your repository with the montoya-api topic, visit your repo's landing page and select "manage topics."