Turn any request into a deliberate security test with parameter-level targeting,
session automation, technology-aware probes, OOB detection, and optional AI analysis.
Download the JAR · Quick start · Scanner catalog · Stepper · Build
| 14 active scanning engines |
10 technology-aware scanners |
7 passive analyzers |
5 framework tools |
1 self-contained JAR |
Important
OmniStrike is explicit by design. Nothing scans proxy traffic automatically. Active scanners and passive analyzers run only when you send a request to OmniStrike from Burp's context menu.
- Pick exactly what to test. Select individual query, body, cookie, JSON, header, and path parameters, then choose the modules to run.
- Keep complex sessions alive. Refresh login cookies or replay multi-step authentication flows before a probe leaves Burp.
- Go beyond generic payload lists. Run focused scanners for modern injection classes, enterprise platforms, cloud products, and API technologies.
- Detect blind behavior. Use Burp Collaborator, ProjectDiscovery Interactsh, or OmniStrike's custom HTTP/DNS OOB listener.
- Keep control of AI. AI analysis is optional, disabled by default, and runs bounded tests for only the vulnerability class you select.
- Review findings in one place. Findings appear in OmniStrike and are forwarded to Burp's Dashboard with request/response evidence.
flowchart LR
A["Request in Burp"] --> B["Send to OmniStrike"]
B --> C["Choose parameters"]
C --> D["Choose modules"]
D --> E["Refresh session / run Stepper"]
E --> F["Active + passive analysis"]
F --> G["Evidence-backed findings"]
G --> H["OmniStrike UI"]
G --> I["Burp Dashboard"]
Download omnistrike.jar, then open:
Burp Suite → Extensions → Installed → Add → Java
Select the JAR and open the new OmniStrike tab.
In Proxy, Repeater, or another Burp request editor:
Right-click request → Send to OmniStrike (All Modules)
Tick the parameters and modules you want, then start the scan. Static assets such as JavaScript, CSS, and images are skipped by active injection modules automatically.
Tip
Manual scans bypass OmniStrike's scan deduplication, so sending the same request again performs a real rescan.
| Engine | Coverage highlights |
|---|---|
| SQL injection | Error, UNION, time-based, and OOB probes across major DBMS families; REST path support. |
| NoSQL operator injection | Safe $eq/$ne and $regex control pairs for query, form, and nested JSON inputs; findings require stable independent confirmation. |
| Command injection | Output, timing, and OOB confirmation for Unix, Windows, and server-side JavaScript contexts. |
| SSRF | Collaborator/OOB callbacks, localhost bypasses, DNS rebinding, and protocol-oriented payloads. |
| SSTI | Fingerprints and probes for 20 template-engine families with reflection guards. |
| XXE | XML, XInclude, JSON-to-XML, content-type forcing, and OOB entity resolution. |
| Path traversal / LFI | Unix and Windows targets, encoding variants, PHP wrappers, and multi-marker confirmation. |
| GraphQL | Introspection bypass, IDOR, injection, error disclosure, and configurable DoS checks. |
| CORS | Reflected origins, null origin trust, subdomain trust, downgrade cases, and credential combinations. |
| Web cache poisoning | Unkeyed headers and parameters with canary-based confirmation. |
| Host header injection | Reset poisoning, routing SSRF, duplicate Host behavior, and override headers. |
| HTTP parameter pollution | Duplicate-parameter precedence and parameter-splitting behavior. |
| Prototype pollution | Server-side proto and constructor.prototype probes with persistence canaries. |
| Deserialization | Format detection, active payloads, and language-specific gadget-chain workflows. |
These scanners join All Modules only after the response indicates the relevant product or protocol:
Dynamics 365 FetchXML
SAP OData
Salesforce SOQL
Firebase / Firestore
SharePoint CAML
ServiceNow GlideRecord
Apache Solr
Odoo Domain Filters
Elasticsearch
Spring Boot Actuator
This response-gated design avoids firing product-specific payloads at unrelated targets.
Passive modules inspect the request and response you explicitly send; they do not create additional traffic.
| Analyzer | Looks for |
|---|---|
| Client-Side Analyzer | DOM XSS flows, prototype-pollution sinks, and exposed secrets. |
| Hidden Endpoint Finder | Routes and endpoints embedded in HTML and JavaScript. |
| Subdomain Collector | Hostnames discovered in response content. |
| Security Header Analyzer | Missing or risky browser security controls. |
| Technology Fingerprinter | Frameworks, platforms, servers, and version disclosure. |
| Sensitive Data Exposure | JWTs, cloud identifiers, payment data, SSNs, IBANs, and other secrets. |
| Error Disclosure Scanner | Strong framework, runtime, database-driver, and stack-trace signatures across normal and error status codes. |
The Error Disclosure Scanner reads at most 512 KB of textual response data, recognizes vendor +json/+xml media types, and keeps exact response evidence for Burp highlighting. A 4xx response is not automatically safe: malformed-input responses are a common place for Jackson, framework, and database exceptions to escape.
| Tool | Purpose |
|---|---|
| AI Vulnerability Analyzer | Optional LLM-guided analysis using Claude, Gemini, Codex, OpenCode, Kimi, Grok, or supported API providers. |
| Deserialization Generator | Copy-ready payloads from 137+ gadget chains across six languages. |
| File Payload Generator | PDF, SVG, DOCX, XLSX, XXE, web-shell, polyglot, EICAR, and inline test payloads. |
| Wordlist Generator | Domain-scoped passive word harvesting for fuzzing and discovery. |
| TLS Analyzer | Protocol/cipher probes plus explicit hostname, validity, key, signature, self-signature, and Java trust-store checks. |
The primary context-menu entry opens a single parameter-and-module picker.
| Context-menu action | Result |
|---|---|
| Send to OmniStrike (All Modules) | Opens the parameter and module picker. |
| Send to OmniStrike ▸ | Runs one selected module as a deterministic Normal Scan or a bounded Targeted AI Test. |
| Set as Session Login Request | Keeps a login/refresh request in memory for Session Keep-Alive. |
| Send to Stepper | Adds the request to a prerequisite chain. |
OmniStrike can target:
- Query, form, cookie, and JSON parameters
- Embedded parameters in
RefererandOrigin - Security-relevant injectable headers
- Individual URL path segments
Each active scanner runs once per selected parameter. Passive analyzers run alongside the chosen workflow without sending extra requests.
Use Session Keep-Alive when a reusable session expires during testing:
- Right-click the login or refresh request.
- Select Set as Session Login Request.
- Enable Session Keep-Alive in the OmniStrike tab.
- Choose the refresh interval.
OmniStrike replays the request, captures fresh cookies, and injects a cookie only when its Domain, Path, and Secure scope matches the outbound request.
Note
The credential-bearing login request is memory-only and must be selected again after Burp restarts. OmniStrike persists the refresh interval, not the raw login request.
Stepper prepares stateful requests by replaying their prerequisites. It is designed for login flows, CSRF tokens, session refreshes, chained API calls, and single-use values.
sequenceDiagram
participant B as Burp / Scanner
participant S as Stepper
participant T as Target
B->>S: Final request with {{itemId}}
S->>T: POST /login
T-->>S: Set-Cookie + {{token}}
S->>T: GET /me using {{token}}
T-->>S: {{userId}}
S->>T: GET /users/{{userId}}/items
T-->>S: {{itemId}}
S->>T: Final request with fresh state
T-->>B: Response
| Capability | Behavior |
|---|---|
| Scanner-safe matching | Exact endpoint matching plus a conservative one-segment dynamic-ID match recognizes mutated scanner requests without wildcarding static routes. |
| Automatic variables | A placeholder such as {{token}} is resolved from earlier headers, cookies, nested JSON, or response bodies. |
| Scoped cookie jar | Cookies follow host/domain, path, and Secure rules across steps and into the final request. |
| Pinned values | Manually supplied variables and cookies survive chain runs and override extracted values. |
| Cached mode | Reuses only a successful chain whose TTL, step count, request/rule fingerprint, and configuration still match. |
| Per-request mode | Runs a fresh isolated chain for every request that consumes a single-use token; scanner workers can prepare independently. |
| Failure handling | Failed, timed-out, or unresolved prerequisite chains clear partial state and prevent matched OmniStrike probes from sending. A short backoff avoids retry storms. |
| Pause / resume | Stops new chains and halts active chains at the next step boundary. |
| Recursion protection | Chain traffic cannot trigger another copy of the same chain. |
Open the Stepper setup guide
Open the Stepper tab and tick Stepper Enabled.
Right-click each request and choose Send to Stepper. Add them in execution order, then use the toolbar to reorder, disable, edit, or remove steps.
Edit a later step or final request and replace changing values with placeholders:
Authorization: Bearer {{access_token}}
GET /api/users/{{userId}}/items/{{itemId}}Stepper searches the newest earlier responses in this order:
- Header with the requested name
Set-Cookiewith the requested name- Matching JSON key, including nested objects and arrays
- A body fallback for common JSON and
name=valueforms
Use an explicit extraction rule when a response contains duplicate names, when the variable should have a different name, or when a value lives in unusual markup.
| Cached mode | Per-request mode | |
|---|---|---|
| Chain runs | Once per successful TTL window | Once for every matched outgoing request |
| Best for | Reusable login sessions and cookies | Single-use CSRF tokens and one-time nonces |
| Throughput | Higher | Limited by chain duration and concurrency |
| Auth-server load | Lower | Higher |
Click Run Chain and inspect Current Variables, Cookie Jar, and Activity Log. Use Invalidate Cache to force the next request to prepare fresh state.
[!NOTE] OmniStrike's own module requests fail closed when Stepper cannot prepare them. Burp's native HTTP-handler API does not expose a request-cancel action, so native Scanner/Repeater traffic is best-effort: OmniStrike logs the failed preparation and leaves that request unchanged.
OmniStrike exposes one callback abstraction with three backends:
- Burp Collaborator when available
- Custom OOB with built-in HTTP and DNS listeners
- Interactsh / External OAST using a ProjectDiscovery public or self-hosted server, with optional token authentication
The custom listener makes blind testing possible without Burp Professional, but it must be reachable from the target. Bind and expose listener ports only on networks you trust, and stop the listeners when the assessment ends.
Interactsh mode registers an isolated session, generates a fresh correlated subdomain for every probe, decrypts polled interactions locally, and forwards confirmed DNS, HTTP, SMTP, and LDAP events through the same finding pipeline. The server address is remembered; the optional authentication token is held in memory only and is never persisted.
Warning
Use only an OOB service you trust. OOB payloads are sent by the target directly to that service and can include target-derived values for proof or correlation. This traffic does not pass through AI redaction. Disable OOB testing when assessment rules prohibit third-party callbacks or data egress.
The TLS Analyzer opens direct, bounded connections from Burp's Java process. It normalizes DNS, IDN, IPv4, and IPv6 targets; sends SNI only for DNS names; probes each locally usable protocol; optionally enumerates the cipher suites available to the JVM; and inspects the returned X.509 chain.
Certificate checks cover hostname/SAN matching, current validity, expiry, signature and public-key strength, cryptographically verified self-signing, and trust against Burp's Java runtime trust store. Hostname verification is performed explicitly after the permissive inspection handshake, so an untrusted certificate cannot hide a name mismatch.
Note
This is a JSSE-based analyzer, not a replacement for a raw OpenSSL/testssl.sh assessment. Blocked by JDK means the local runtime prevented a meaningful probe. Not supported means no handshake was negotiable with the protocol and cipher implementations available to that JVM. The UI preserves that distinction instead of turning an inconclusive local limitation into a confirmed server finding.
The AI Vulnerability Analyzer is disabled by default. It supports:
- Local CLI workflows for Claude, Gemini, Codex, OpenCode, Kimi, and Grok
- API-key workflows for Anthropic, OpenAI, Google, xAI, Moonshot AI, DeepSeek, Mistral, Groq, OpenRouter, and Ollama
- Editable model identifiers so newer compatible models can be used without waiting for a UI update
Redact AI Data is enabled by default. Every prompt crosses one shared privacy boundary immediately before it reaches an API or CLI backend. OmniStrike replaces sensitive values with stable, typed placeholders while retaining enough structure for useful analysis:
POST https://[REDACTED_HOST_1]/api/orders?id=[REDACTED_QUERY_VALUE_1]
Authorization: Bearer [REDACTED_AUTH_1]
Cookie: session=[REDACTED_COOKIE_1]
Content-Type: application/json
{"email":"[REDACTED_EMAIL_1]","action":"view"}The original Burp request is never modified. Authentication cookies and headers remain available to OmniStrike's local probe engine, so the scanner can still test an authenticated endpoint; only the AI-facing copy is sanitized.
Redaction covers authorization headers, every cookie value, private/custom headers, URL credentials and hosts, query and form values, sensitive JSON/XML fields, emails, payment cards, phone numbers, national IDs, SSNs, IBANs, IP/MAC addresses, UUIDs, private keys, known provider tokens, and unknown high-entropy secrets. Repeated values receive the same placeholder within a prompt so the model can reason about data flow.
Mask UI Data is a separate option for shoulder-surfing and screen sharing. It masks captured values in findings, HTTP viewers, logs, Stepper state, attack-surface hosts, tables, clipboard copies, and exports without changing the stored evidence.
Caution
Redaction is defense in depth, not a mathematical guarantee: an unusual client-specific value can evade any local detector. For engagements that prohibit third-party disclosure, use a locally hosted model/CLI or leave AI disabled. CLI backends also process attacker-controlled response text and may expose local tool capabilities depending on the CLI's own configuration; use them only in an isolated environment.
For an active module, the context menu offers two deliberate choices:
| Action | Behavior |
|---|---|
| Normal Scan | Runs OmniStrike's deterministic scanner and built-in verification logic for the selected module. |
| Targeted AI Test | Asks the configured model for a small set of high-signal probes for only the selected vulnerability class, sends them through Burp, and reviews the resulting evidence. |
A Targeted AI Test sends at most 12 probe requests. It completes after that single bounded pass: there are no legacy Smart Fuzzing batches, adaptive follow-up rounds, or separate WAF-bypass loops. Passive-only analyzers remain passive and do not generate attack traffic.
Command-injection AI testing requires an active OOB backend. OmniStrike supplies the model with an OOB placeholder, replaces it with a fresh correlated Burp Collaborator, Interactsh, or custom-listener hostname for each probe, and continues monitoring after the request pass completes. Matching callbacks are reported as confirmed findings. SQL injection and other modules can also use correlated OOB probes when the selected model proposes them.
The model proposes tests; OmniStrike still controls request mutation, authenticated delivery, response capture, OOB correlation, scope filtering, and finding creation. CLI output is normalized before parsing so provider banners, progress messages, and echoed prompts cannot be mistaken for the model's structured result.
| Control | Description |
|---|---|
| Threads | Shared active-scan pool from 1 to 100 workers. |
| Throttle | None, adaptive backoff, or a fixed delay. |
| Time-based testing | Separately gates slower blind timing checks. |
| Static-resource skip | Avoids active injection against common asset extensions. |
| Targeted AI probes | One module-specific pass with a hard maximum of 12 requests and no adaptive or WAF-bypass rounds. |
| Redact AI Data | Sanitizes the AI-facing prompt at the shared provider boundary; enabled by default. |
| Mask UI Data | Optionally masks captured target data across views, copies, and exports. |
| Themes | 29 UI themes, scoped to OmniStrike or optionally applied globally. |
- JDK 17 or newer
- Git
git clone https://github.com/worldtreeboy/OmniStrike.git
cd OmniStrike
./gradlew test shadowJarWindows users can run the wrapper from Git Bash or WSL.
The ready-to-load extension is written to:
build/libs/omnistrike.jar
The shadow JAR:
- Leaves the Montoya API out because Burp provides it at runtime
- Relocates OmniStrike's Gson dependency to prevent extension classpath conflicts
- Keeps gadget-chain package names intact so generated serialized payloads remain valid
- Fork the repository and create a focused branch.
- Add tests for behavioral changes where practical.
- Run
./gradlew test shadowJar. - Validate scanning changes only against systems you own or are authorized to test.
- Open a pull request with the problem, approach, and verification notes.
Bug reports and feature ideas are welcome in GitHub Issues.
| worldtreeboy Author & maintainer |
Claude AI pair programmer |
Codex AI pair programmer |
Kimi AI pair programmer |
v1.86 — Stateful scan preparation and analyzer correctness
- Reworked Stepper preparation for active scanning: matched OmniStrike probes now fail closed when prerequisites fail, time out, are paused, or leave required variables unresolved.
- Added fingerprinted TTL caches, isolated per-request state, conservative dynamic path matching, bounded prerequisite timeouts, short failure backoff, and cleanup of partial variables/cookies.
- Prevented disabled or missing prerequisites from reusing stale extracted values, and prevented TTL changes from resurrecting an older cache snapshot.
- Fixed Error Disclosure finding loss under concurrent traffic, bounded body conversion before decoding, preserved exact Burp response markers, recognized vendor structured media types, and restored strong detections in 4xx responses.
- Tightened noisy error signatures and expanded regression coverage across Java, Jackson, Spring, Python, Django, Werkzeug, PHP, Laravel, .NET, Ruby, Node.js, Go, and database errors.
- Corrected TLS hostname verification, SNI behavior for IP literals, local-JDK protocol classification, IPv6 finding URLs, cancellation/UI races, recent-expiry handling, future-validity checks, cryptographic self-signature checks, and trust-store reporting.
- Prevented inconclusive or locally blocked TLS 1.2/1.3 probes from becoming confirmed "not supported" findings.
- Verified the complete project with 195 tests, zero failures, and a clean shaded-JAR build.
v1.84 — Conservative NoSQL operator injection
- Added a dedicated NoSQL operator-injection scanner for query, form, and nested JSON values using non-executable
$eq/$neand$regexcontrol pairs. - Findings require a stable baseline, repeatable true/false behavior, and confirmation by an independent operator family; reflected payloads, WAF responses, and response-length-only changes are rejected.
- Added request-safety guards for mutating paths, destructive action parameters, unknown POST endpoints, pathological JSON, bounded probe counts, throttling, and cancellation.
- Added a module-specific Targeted AI Test path that preserves operator objects structurally and rejects
$where, JavaScript, unsafe regular expressions, non-JSON injection points, and unrelated payloads. - Verified the complete project with 157 tests and a clean shaded-JAR build.
v1.83 — Full scanner hardening and verified release
- Audited every active scanner, passive analyzer, OOB path, session workflow, and shared scan primitive; added regression coverage for the confirmed failure modes.
- Corrected structured JSON/XML mutation, endpoint-scoped OOB confirmation, baseline-aware SSRF evidence, CORS authentication semantics, SQLi/SSTI/command-injection verification, and deserialization payload reliability on Java 17.
- Made high-impact scanners explicit/manual-only where appropriate and disabled destructive, state-changing, data-exfiltration, and timing-heavy probes by default.
- Added Burp Collaborator, Interactsh, and custom OOB backends with safer placeholder expansion, bounded parsing, absolute connection deadlines, and per-payload correlation.
- Hardened Session Keep-Alive and Stepper origin, redirect, cookie, cache, framing, persistence, and shutdown behavior.
- Bounded scan queues, subprocess/API output, passive discovery stores, deduplication caches, response parsing, and AI state; rejected work is now visible instead of silently disappearing.
- Kept AI redaction default-on, removed API-key persistence, reduced CLI prompt exposure, and preserved authenticated local scanning while sanitizing only the AI-facing copy.
- Replaced open-ended AI fuzzing workflows with a bounded Targeted AI Test: one selected module, at most 12 focused probes, scope-filtered evidence review, and mandatory correlated OOB testing for command injection.
- Isolated structured CLI results from provider banners and transcripts across supported AI backends, preventing malformed-output retries and silently lost findings.
- Confirmed all scanning remains explicitly right-click-driven; no active or passive module runs automatically on proxy traffic.
v1.82 — Privacy boundary and visual redesign
- Added default-on, structure-preserving redaction before every API-key and CLI AI backend.
- Added optional UI privacy masking across evidence viewers, findings, logs, Stepper state, attack-surface data, copies, and exports.
- Introduced the Omni Pro design system with a branded header, collapsible command controls, modern tables and tabs, painted rounded controls, redesigned workspace navigation, and a responsive welcome state.
- Preserved Burp's native theme as a permanent option and kept global theming explicitly opt-in.
- Added adversarial regression tests for credentials, cookies, structured bodies, PII, payment data, infrastructure identifiers, provider tokens, private keys, high-entropy secrets, stability, and false positives.
v1.81 — Security hardening and scanner reliability
- Scoped Session Keep-Alive redirects and cookies to their intended origins, paths, and transport security requirements; login requests now remain memory-only.
- Hardened the custom DNS OOB parser and Stepper's cross-origin cookie handling and successful-chain cache semantics.
- Preserved distinct findings during deduplication and made Dashboard finding bundling race-safe.
- Restored JSON payload injection across six scanners, including nested XXE targeting, and made rejected AI scan jobs visible and recoverable.
- Added regression tests for findings deduplication, session origin/cookie rules, and Stepper cookie matching.
v1.80 — Provider expansion and scanner reliability
- Added API-key mode for ten providers: Anthropic, OpenAI, Google Gemini, xAI, Moonshot AI, DeepSeek, Mistral, Groq, OpenRouter, and Ollama.
- Added structured CLI output handling for Grok and Kimi.
- Fixed GraphQL scans without a captured response and guarded the deep-nesting check against null bodies.
- Corrected bundled Dashboard severity and confidence aggregation.
v1.79 — Kimi, Grok, and unattended CLI workflows
- Added Kimi CLI and Grok CLI backends.
- Added backend-specific structured-output and prompt-delivery handling.
- Enabled headless approval modes for supported CLI backends.
- Added clear handling for oversized Kimi argv prompts.
v1.78 — SQL injection reporting
- Promoted confirmed multi-marker error-based SQL injection to a real HIGH/FIRM finding.
- Made manual SQLi rescans bypass the module's internal tested-parameter cache.
- Removed an unimplemented boolean-blind claim from the module description.
v1.77 — Stability and hot-path performance
- Prevented a latent AI CLI subprocess pipe deadlock.
- Fixed SQLi UNION and Dynamics FetchXML array-index edge cases.
- Hoisted frequently compiled scanner regular expressions into reusable constants.
v1.76 — Explicit scanning and false-positive reduction
- Made passive analyzers right-click-only.
- Reworked SSTI fingerprints around evaluated, engine-specific evidence.
- Hardened path-traversal baseline and marker logic.
- Converted Dashboard finding details to plain text.
v1.75 and earlier
- Forwarded findings without native HTTP exchanges to Burp using synthetic requests.
- Added persistence for non-secret settings while keeping API keys out of storage.
- Reduced JAR conflicts by excluding Montoya and relocating Gson.
- Added the parameter/module picker, manual dedup bypass, and Session Keep-Alive integration.
- Moved deserialization tooling into Framework Tools and removed the noisy LDAP injection scanner.
OmniStrike is built for authorized penetration testing and security research. Use it only against systems you own or have explicit written permission to test. Active probes can change application state, trigger defenses, or affect availability.
See the MIT License for the software license. The authors are not responsible for misuse.
Built on Burp's Montoya API.
One request. The right probes. Fresh state. Clear evidence.