Burp Plugins
- Autorize - To Test BACs
- Burp Bounty - Profile-based Scanner
- Active Scan++ - Add more power to Burp's Active Scanner
- AuthMatrix - Authorization/PrivEsc Checks
- Broken Link Hijacking - For BLH
- Collaborator Everywhere - Pingback/SSRF
- Command Injection Attacker
- Content-Type Converter - Trying to bypass certain restrictions by changing Content-Type
- Decoder Improved - More Decoder Features
- Freddy - Deserialization
- Flow - Better HTTP History
- Hackvertor - Handy type conversion
- HTTP Request Smuggler
- Hunt - Potential Vuln Identifier
- InQL - GraphQL Introspection testing
- J2EE Scan - Scanning J2EE Apps
- JSON/JS Beautifier
- JSON Web Token Attacker
- ParamMiner - Mine Hidden Parameters
- Reflected File Download Checker
- Reflected Parameter - Potential Reflection
- SAML Raider - SAML Testing
- Upload Scanner - File Upload Tester
- Web Cache Deception Scanner
Credits: https://twitter.com/harshbothra_/status/1299720306777415680