Hercules | DAST Hercules מאת
Powerful web application security scanner. Analyze XSS, SQLi, ports, API, S3, subdomains and more.
נתוני העל של ההרחבה
צילומי מסך
על אודות הרחבה זו
Hercules DAST (Dynamic Application Security Testing) — a professional tool for web application security analysis directly in your browser.
🔍 Features:
• robots.txt — sensitive paths analysis (/admin, /api, /.env, /backup)
• sitemap.xml — hidden and sensitive URL discovery
• Scripts — HTTP/HTTPS check, external scripts, outdated libraries
• DOM XSS — vulnerability detection (innerHTML, eval, document.write)
• Forms — CSRF tokens, passwords in GET, autocomplete
• Security Headers — CSP, X-Frame-Options, X-Content-Type-Options
• Cookies — sensitive cookie analysis
• CORS — wildcard origin check
• Ports — open port scanning (80,443,8080,8443,3000,5000,8000)
• API endpoints — Swagger, OpenAPI, GraphQL discovery
• SQL injection — active form testing
• XSS test — active form testing
• Directories — brute force common paths (admin, .env, backup, .git)
• S3 buckets — open AWS S3 bucket discovery
• Subdomains — crt.sh and common subdomain enumeration
📊 Results are displayed with severity statistics (Critical, High, Medium, Low) and can be exported to JSON or HTML.
🛡️ All data is processed locally — nothing is sent to external servers.
Developed for pentesters, developers, and security professionals.
🔍 Features:
• robots.txt — sensitive paths analysis (/admin, /api, /.env, /backup)
• sitemap.xml — hidden and sensitive URL discovery
• Scripts — HTTP/HTTPS check, external scripts, outdated libraries
• DOM XSS — vulnerability detection (innerHTML, eval, document.write)
• Forms — CSRF tokens, passwords in GET, autocomplete
• Security Headers — CSP, X-Frame-Options, X-Content-Type-Options
• Cookies — sensitive cookie analysis
• CORS — wildcard origin check
• Ports — open port scanning (80,443,8080,8443,3000,5000,8000)
• API endpoints — Swagger, OpenAPI, GraphQL discovery
• SQL injection — active form testing
• XSS test — active form testing
• Directories — brute force common paths (admin, .env, backup, .git)
• S3 buckets — open AWS S3 bucket discovery
• Subdomains — crt.sh and common subdomain enumeration
📊 Results are displayed with severity statistics (Critical, High, Medium, Low) and can be exported to JSON or HTML.
🛡️ All data is processed locally — nothing is sent to external servers.
Developed for pentesters, developers, and security professionals.
מדורג 0 על־ידי 0 סוקרים
הרשאות ונתונים
הרשאות נדרשות:
- גישה ללשוניות
- גישה לנתונים שלך מכל האתרים
איסוף נתונים:
- המפתח אומר שהרחבה זו אינה דורשת איסוף נתונים.
מידע נוסף
- גרסה
- 1.0.0
- גודל
- 63.47 ק״ב
- עדכון אחרון
- לפני 11 ימים (27 מרץ 2026)
- קטגוריות קשורות
- היסטוריית הגרסאות
- הוספה לאוסף