Item logo image for Геркулес | DAST

Геркулес | DAST

5.0(

1 rating

)
ExtensionTools2 users
Item media 1 (screenshot) for Геркулес | DAST

Overview

Расширение для анализа и оценки защищенности приложения.

Hercules DAST (Dynamic Application Security Testing) — a professional tool for web application security analysis directly in your browser. 🔍 Features: • robots.txt — sensitive paths analysis (/admin, /api, /.env, /backup) • sitemap.xml — hidden and sensitive URL discovery • Scripts — HTTP/HTTPS check, external scripts, outdated libraries • DOM XSS — vulnerability detection (innerHTML, eval, document.write) • Forms — CSRF tokens, passwords in GET, autocomplete • Security Headers — CSP, X-Frame-Options, X-Content-Type-Options • Cookies — sensitive cookie analysis • CORS — wildcard origin check • Ports — open port scanning (80,443,8080,8443,3000,5000,8000) • API endpoints — Swagger, OpenAPI, GraphQL discovery • SQL injection — active form testing • XSS test — active form testing • Directories — brute force common paths (admin, .env, backup, .git) • S3 buckets — open AWS S3 bucket discovery • Subdomains — crt.sh and common subdomain enumeration 📊 Results are displayed with severity statistics (Critical, High, Medium, Low) and can be exported to JSON or HTML. 🛡️ All data is processed locally — nothing is sent to external servers. Developed for pentesters, developers, and security professionals.

Details

  • Version
    1.0.3
  • Updated
    March 31, 2026
  • Offered by
    Hercules
  • Size
    50.53KiB
  • Languages
    русский
  • Developer
    Email
    ascanio.trovato.nice@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps