Ross ROSS = Recommend OSS · open-source software intelligence for agents

outlaws-bai/Galaxy

一个想让你测试加密流量像测试明文一样简单高效的 Burp 插件。 A Burp plugin that makes testing encrypted traffic as simple and efficient as testing plaintext. observed · 2026-08-28

github.com/outlaws-bai/Galaxy · Java · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

88/100

  • Activity 99
  • Release rhythm 87
  • Longevity 65
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 33
  • age_days: 917
  • days_rel: 9
  • days_push: 9
  • n_releases_24m: 14

Full methodology

Adoption not part of the score

1109 stars · 72 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Galaxy is a Burp Suite extension that automatically decrypts and re-encrypts HTTP traffic whose payloads are encrypted, letting testers work with plaintext in Proxy, Repeater, Intruder, and Scanner. It supports custom hooks for complex encryption logic and integrates with tools like sqlmap and xray for scanning decrypted requests.

Use cases

  • decrypt encrypted HTTP request and response bodies in Burp Suite
  • test web APIs that encrypt traffic with custom or combined algorithms
  • send decrypted plaintext requests to sqlmap for SQL injection scanning
  • forward decrypted requests to xray for automated vulnerability scanning
  • hook client-side code to reverse and invoke a site's encryption logic
  • fuzz encrypted parameters with Burp Intruder in plaintext

When to choose

  • you are pentesting a site whose HTTP messages are encrypted
  • encryption logic is complex, e.g. algorithm combinations, custom ciphers, or dynamic keys
  • you want scanners like sqlmap or xray to work against encrypted traffic
  • you can reverse the site's crypto logic or hook its client code

When to avoid

  • traffic is plain HTTP/HTTPS without application-layer encryption
  • you cannot reverse or hook the site's encryption logic
  • you need a standalone proxy outside Burp Suite

Facets

plugin · maturity active

security penetration-testing proxy middleware security penetration-testing web-development jvm burpsuite burp-extension traffic-decryption mitm encrypted-traffic pentest sqlmap xray desktop

1 source

Member repositories

RepositoryRoleHealth v2
outlaws-bai/Galaxymain88

For agents

markdown · JSON · MCP: product_card(name="outlaws-bai/Galaxy")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem