Try searching for "database", "file", "API", or browse by category
11 Tools in Burp Extensions
hackvertor
by PortSwigger
Hackvertor is a tag based conversion tool written in Java implemented as a Burp Suite extension
formatify
by dr34mhacks
Formatify is a Burp Suite extension that instantly converts HTTP requests into multiple formats like cURL, Python, PowerShell, and more—saving time and streamlining your workflow. 🚀
office-open-xml-editor
by PortSwigger
Burp extension that add a tab to edit Office Open XML document (xlsx,docx,pptx)
burp-co2
by JGillam
A collection of enhancements for Portswigger's popular Burp Suite web penetration testing tool.
burp-JS-Miner
by minamo7sen
This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.
JavaSerialKiller
by NetSPI
Burp extension to perform Java Deserialization Attacks
Java-Deserialization-Scanner
by federicodotta
All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
AutoRepeater
by nccgroup
Automated HTTP Request Repeating With Burp Suite
Autorize
by Quitten
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
AuthMatrix
by SecurityInnovation
AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.
reflector
by elkokc
Burp plugin able to find reflected XSS on page in real-time while browsing on site
Infosec Certifications Resources
Discover the best cybersecurity certifications to advance your career








































Frequently Asked Questions about InfosecMania
Learn more about Cybersecurity Tools and how they can enhance your security posture
InfoSecMania is a comprehensive directory of cybersecurity tools and resources designed to help security professionals find the right tools for their needs.
You can submit a tool by clicking on the 'Submit Tool' link in the navigation menu and filling out the submission form with details about your tool.
No, InfoSecMania includes both free and commercial tools. Each tool listing indicates whether it's free, paid, or offers a freemium model.
Tools are categorized based on their primary function, such as penetration testing, vulnerability assessment, network security, etc. Many tools may appear in multiple categories if they serve multiple purposes.
We only list tools and resources from publicly available, reputable sources — most of which are open-source and widely used in the cybersecurity community. However, always review and test tools in a safe, legal environment, like your lab or VM.
We actively monitor public repositories, GitHub, and community forums to keep our tool listings fresh. Many tools are auto-sourced from open-source feeds and security communities.