→ كل المشاريع

BurpJSReconRadar

بواسطة @ab2pentest

نشِط 25

Burp Suite extension for passive JS reconnaissance - detects 1,600+ secret patterns, API keys, endpoints, and security misconfigurations in HTTP responses in real-time.

عن هذا المشروع

JSReconRadar A comprehensive Burp Suite extension for passive reconnaissance of JavaScript files. Detects secrets, API keys, endpoints, sensitive data, and security misconfigurations in HTTP responses in real-time. Works on both Burp Suite Community and Professional editions. Features Detection (1,600+ patterns) Category Examples Severity ---------- ---------- ---------- API Keys & Tokens AWS, GCP, Azure, Stripe, GitHub, GitLab, Slack, Twilio, SendGrid, Shopify, Firebase, Discord, Telegram, Mapbox, and 30+ more services HIGH AI API Keys OpenAI, Anthropic, Groq, Replicate, HuggingFace, Cohere, Mistral, Deepseek, Together AI, LangSmith, Pinecone, Voyage AI HIGH Private Keys & Credentials RSA/DSA/EC/PGP private keys, HTTP Basic Auth, Bearer tokens, JWTs, hardcoded passwords CRITICAL Database Connection Strings Redis, MongoDB, PostgreSQL, MySQL, AMQP URIs with credentials CRITICAL JS Config Secrets key:"value" patterns in JS objects, escaped JSON-in-JS (\"key\":\"value\"), DSN configs, connection strings CRITICAL/HIGH API Endpoints /api/, /rest/, /graphql, /auth/, /admin/, /internal/, /debug/, /login, /logout, /token, /webhook, /ws/, and more INFO

من ملف README الخاص بالمشروع على GitHub

النجوم
25
التفريعات
5
آخر تحديث
23/04/2026

أضف هذه الشارة إلى ملف README

أظهر أن مشروعك مُدرج على «صُنع في الجزائر».

Made in Algeria
[![Made in Algeria](https://www.madeinalgeria.dev/badge/burpjsreconradar.svg)](https://www.madeinalgeria.dev/projects/burpjsreconradar)

مشاريع ذات صلة