# 1N3/IntruderPayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

Repository: https://github.com/1N3/IntruderPayloads
Canonical: https://ross.abutalabs.com/products/intruderpayloads
Homepage: https://xerosecurity.com
Language: BlitzBasic
License Family: other
Topics: burpsuite, intruder, payloads, fuzz-lists, fuzzing, fuzz, injection, burpsuite-engagement, burpsuite-intruder, attack, sql-injection, bugbounty
Last push: 2021-09-27T01:47:05+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3961, "days_push": 1802, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3970, forks 1179 (observed 2026-08-28T04:08:30.829735+00:00)

## What it is
A curated collection of Burp Suite Intruder and BurpBounty payloads, fuzz lists, malicious file upload samples, and web pentesting methodologies/checklists maintained by the Sn1per Security author. It is a static resource repository rather than executable software, with an install script to pull third-party payload repos.

## Use cases
- fuzz web app parameters with burp intruder payload lists
- find sql injection and xss payloads for bug bounty hunting
- test malicious file upload handling
- follow an owasp web application testing checklist during a pentest
- load fuzz lists into burp bounty or ffuf
- build a wordlist for web vulnerability scanning

## When to choose
- you need battle-tested payload and fuzz lists for Burp Suite or other web scanners
- you want OWASP-aligned pentesting checklists and methodologies in one place
- you are a bug bounty hunter or pentester building a payload arsenal

## When to avoid
- you need an actively updated payload repository with recent commits
- you want a tool that runs scans itself rather than static lists
- you require a permissively licensed dataset since this repo has no license

## Facets
- artifact type: dataset
- maturity: maintenance
- function: penetration-testing, fuzzing, security, vulnerability-scanning
- domain: security, penetration-testing, developer-tools
- platform: cross-platform, cli
- tags: burpsuite, payloads, fuzz-lists, wordlists, sql-injection, xss, bugbounty, owasp, pentesting-checklists, file-upload

## Member repositories
- 1N3/IntruderPayloads (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:30.829735+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:24:21.968375+00:00, confidence not recorded.
  - readme: https://github.com/1N3/IntruderPayloads (fetched 2026-08-28T04:08:30.829735+00:00, sha 1ddd73032091)
  - homepage: https://xerosecurity.com (fetched 2026-08-29T09:18:02.175008+00:00, sha f9d88a08e490)
  - site_page: https://sn1persecurity.com/wordpress/about (fetched 2026-08-29T09:18:02.177992+00:00, sha 88b6a0087c2f)
  - site_page: https://sn1persecurity.com/wordpress/documentation (fetched 2026-08-29T09:18:02.179815+00:00, sha cd49aeb6b655)
  - site_page: https://sn1persecurity.com/wordpress/integrations (fetched 2026-08-29T09:18:02.183281+00:00, sha 2da70831d1a7)
  - site_page: https://sn1persecurity.com/wordpress/external-attack-surface-management-with-sn1per (fetched 2026-08-29T09:18:02.185060+00:00, sha e0907592f9d1)
  - site_page: https://sn1persecurity.com/wordpress/sn1per-professional-2026-release (fetched 2026-08-29T09:18:02.186877+00:00, sha d6a4c724acda)
  - site_page: https://sn1persecurity.com/wordpress/faq (fetched 2026-08-29T09:18:02.181518+00:00, sha 093ed2dba210)
- Data as of 2026-08-30T08:39:29.467469+00:00.
