# sleeyax/burp-awesome-tls

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Repository: https://github.com/sleeyax/burp-awesome-tls
Canonical: https://ross.abutalabs.com/products/burp-awesome-tls
Language: Java
License: GPL-3.0
License Family: copyleft
Topics: burpsuite, burp-extensions, tls, tls-fingerprint, java, golang, go, utls, burp-suite, burp-cloudflare-bypass, burp-waf, burp, ja3, ja3-fingerprint, burp-ja3
Last push: 2026-08-24T21:05:06+00:00

## Health v2 (maintenance only)
Score: 89/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 69, longevity 100
- inputs: {"age_days": 1683, "days_push": 9, "days_rel": 208, "gap_med": 7, "n_releases_24m": 4}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1889, forks 118 (observed 2026-08-28T04:05:49.441679+00:00)

## What it is
A Burp Suite extension that hijacks Burp's HTTP and TLS stack to spoof any browser's TLS fingerprint (JA3). It helps evade WAF bot detection like Cloudflare, Akamai, and DataDome during web security testing.

## Use cases
- bypass cloudflare bot detection in burp suite
- spoof browser tls fingerprint ja3
- evade waf while pentesting with burp
- avoid tls fingerprinting during web scraping
- make burp requests look like a real browser
- bypass akamai and datadome bot protection

## When to choose
- you use Burp Suite for web security testing against WAF-protected targets
- you need customizable JA3/TLS client hello spoofing without forking Burp
- you want a plug-and-play extension that works on Burp Pro and Community

## When to avoid
- you don't use Burp Suite and need a standalone TLS spoofing proxy
- you need a general-purpose HTTP client library rather than a Burp extension
- your use case is not security testing (evasion tooling may violate target policies)

## Facets
- artifact type: plugin
- maturity: active
- function: security, networking, proxy, middleware
- domain: security, penetration-testing, web-development
- platform: cross-platform, jvm, go
- tags: burp-suite, burp-extension, tls-fingerprinting, ja3, waf-bypass, utls, anti-bot-evasion, penetration-testing, desktop

## Member repositories
- sleeyax/burp-awesome-tls (main) score 89

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:49.441679+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:13:10.538583+00:00, confidence not recorded.
  - readme: https://github.com/sleeyax/burp-awesome-tls (fetched 2026-08-28T04:05:49.441679+00:00, sha b38a88adf5d6)
- Data as of 2026-08-30T08:39:29.467469+00:00.
