XSStrike

Cross-site scripting detection suite with context analysis.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About XSStrike

XSStrike crawls a target, analyses where user input lands in the response and generates payloads suited to that context rather than throwing a fixed list, covering reflected and DOM-based cross-site scripting with a WAF fingerprinting stage.

Strengths

  • Builds payloads from the reflection context instead of using a static list
  • Handles DOM-based cases as well as reflected ones

Limitations

  • Only for applications you are authorised to test
  • Upstream development has been quiet

Details

Pricing
FreeThe open-source tool is available without a license fee.
License
Open source, license not stated
Developer
s0md3v
Platforms
Windows, macOS, Linux, Command line
How it runs
Downloadable app
Best suited for
Cross-site scripting detection suite with context analysis
Categories
Security tools
Last verified
Added
Provenance
Selected from the TechWalrus Resource Hub (Cybersecurity & Pentesting); facts checked against the developer's own pages, 2 sources on file.

Report a wrong fact or a dead link on this listing