Professional Community
Agartha is a comprehensive security testing tool that specializes in payload generation for injection vulnerabilities and assessment of authentication and authorization issues. It generates extensive wordlists for SQL Injection, Local File Inclusion (LFI), and Remote Code Execution (RCE) attacks, with support for BCheck integration. The extension also constructs user access matrices to identify privilege escalation paths, performs HTTP 403 bypass testing, converts requests to JavaScript for XSS exploitation, and automates Bambdas script generation.
Right-click any HTTP request and select "Extensions → Agartha → Copy as JavaScript". The generated JavaScript code will be automatically copied to your clipboard.
|
Author |
Author
Volkan Dindar |
|---|---|
|
Version |
Version
3.0.0 |
|
Rating |
Rating |
|
Popularity |
Popularity |
|
Last updated |
Last updated
31 October 2025 |
|
Estimated system impact |
Estimated system impact
Overall impact: Medium
Memory
Low
CPU
Low
General
Medium
Scanner
Low
|
You can install BApps directly within Burp, via the BApp Store feature in the Burp Extender tool. You can also download them from here, for offline installation into Burp.
|
|
You can view the source code for all BApp Store extensions on our GitHub page. |
|
|
Follow @BApp_Store on Twitter to receive notifications of all BApp releases and updates. |
Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.
Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.