-
Notifications
You must be signed in to change notification settings - Fork 1
SecretSifter #329
Copy link
Copy link
Open
Labels
CommunityThis extension is compatible with Burp Suite Community.This extension is compatible with Burp Suite Community.ProfessionalThis extension is compatible with Burp Suite Professional.This extension is compatible with Burp Suite Professional.
Description
Extension URL
https://github.com/secretsifter/secretsifter-burp
Version number
1.0.0
Select additional compatible products and features
- Community
- DAST
- Burp AI
Author display name
Hemanth Gorijala
Contact details (optional)
Discord username (optional)
No response
I confirm that the following is true:
- I have permission from all relevant persons to submit this extension to the BApp Store for public use, under the terms and conditions of the EULA.
- I have read and understood the submission requirements for the BApp Store.
Extension overview
SecretSifter helps security professionals identify hardcoded secrets, tokens, and credentials that are unintentionally exposed in HTTP responses during authorized testing. It fires automatically on every proxied response and sweeps the existing site map on load — no manual configuration needed. Passive scan check and Dashboard issue reporting require Professional. Bulk Scan, proxy handler, context menu rescan, and HTML/CSV export work in Community Edition.
Key features
- 160+ detection rules covering anchored token formats, entropy-based heuristics, generic key-value patterns, and database connection strings
- Passive scan check fires on every proxied response (Pro) and sweeps existing site map on load
- Proxy handler captures findings in Community Edition
- Bulk Scan tab: paste or import URL lists, follow script-src and webpack chunks, HAR import, scope monitor
- Right-click context menu rescan from Proxy History or Repeater
- HTML report export (all-in-one or per-domain ZIP) and CSV export
- Settings: scan tier (FAST/LIGHT/FULL), entropy threshold, CDN blocklist, key name blocklist/allowlist
Usage instructions
- Download secretsifter-1.0.0.jar from the Releases page
- Open Burp Suite → Extensions → Installed → Add
- Set Extension type to Java, browse to the JAR, click Next
- A "Secret Sifter" tab appears in the main tab bar
- Browse your target through Burp — findings appear automatically in Dashboard → Issue Activity (Pro) and the Bulk Scan results table (all editions)
- For bulk scanning: go to Secret Sifter → Bulk Scan, paste URLs, click Start Scan
Template identifier (Internal use only - please ignore)
- template:01-submit-extension
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
CommunityThis extension is compatible with Burp Suite Community.This extension is compatible with Burp Suite Community.ProfessionalThis extension is compatible with Burp Suite Professional.This extension is compatible with Burp Suite Professional.
Type
Projects
Status
Concept review