XSStrike is an advanced XSS scanner written in python. It has a powerful fuzzing engine and provides zero false positive result using fuzzy matching. XSStrike analyses the response with multiple parsers and then crafts payloads that are guaranteed to work by context analysis integrated with a fuzzing engine.

Github仓库以及使用方法: XSStrike XSStrike使用方法

Installation:
git clone https://github.com/s0md3v/XSStrike
pip3 install -r requirements.txt XSStrike Advanced XSS Detection Suite

XSStrike is a Cross Site Scripting detection suite equipped with four hand written parsers, an intelligent payload generator, a powerful fuzzing engine and an incredibly fast crawler.

Instead of injecting payload and checking its work like other tools, XSStrike analyzes the response through multiple parsers, and then guarantees the payload through context analysis integrated with fuzzy matching.

Features:
- Fuzzing and bruteforce parameters for XSS
- Built-in crawler functionality
- WAF detection and bypass attempts
- Supports both GET and POST methods
- Multiprocessing support
- Context analysis
- Configurable core
- Complete HTTP support 