Ghost-Js-Burp-Extension: Burp Suite Extension to Detect Hardcoded Secrets & Endpoints in JavaScript
Summary
A Burp Suite extension using the Montoya API that passively analyzes JS, HTML, and JSON responses for 150+ secret types (cloud credentials, API keys, tokens, private keys) and maps hidden API endpoints. It features active script bundle fetching, background scanning, and false-positive filtering.
Why it matters
Streamlines JavaScript reconnaissance during bug bounty hunting and web penetration testing by uncovering hidden attack surfaces and exposed secrets with minimal noise.
- Published
- Collected
Skip to content