This project hosts security advisories and proof-of-concepts related to Google's research impacting non-Google code.
A Burp Suite plugin designed for automated fuzz testing of file upload vulnerabilities with over 500 payloads.
IDOR Scanner is a Burp Suite extension that automates the detection of IDOR vulnerabilities in web applications.
Scans remote JavaScript files with Trufflehog + Semgrep to detect leaked secrets.
A curated list of practical resources for offensive CI/CD security research since 2021.
jSQL Injection is a Java application for automatic SQL database injection.
A tool for cyberspace asset mapping, ICP filing, equity structure diagrams, domain resolution, and HTTP calls.
fastjson exploitation tool supporting Tomcat and Spring for advanced security testing.