Skip to content

An extension for Burp's Web Vulnerability Scanner that can detect API discovery metadata and extract data useful during recon.

License

Notifications You must be signed in to change notification settings

DanaEpp/APIDiscovery

Repository files navigation

API Discovery

Quality Gate Status Maintainability Rating Security Rating

Bugs Vulnerabilities Code Smells

A Burp Suite extension that leverages APIS.json and api-catalog specifications to detect API metadata that can be used during recon.

This extension will also do API doc path enumeration, based on previous work found in BishopFox's Swagger Jacker. Just faster, and integrated directly in Burp Suite.

This extension taps directly into Burp's Web Vulnerability Scanner, and produces issues on the Dashboard and in the Site Map.

About

An extension for Burp's Web Vulnerability Scanner that can detect API discovery metadata and extract data useful during recon.

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages