BRS-XSS
XSS Vulnerability Scanner
For authorized security research, penetration testing & education
Features
Context-Aware Payloads
HTML, JavaScript, CSS, URI, SVG, XML contexts with intelligent payload selection
WAF Evasion
Bypass Cloudflare, Akamai, AWS WAF, Imperva, ModSecurity, and more
DOM Analysis
Full browser-based DOM XSS detection via Playwright headless browser
Intelligent Classification
Automatic XSS type detection and severity scoring with CVSS
Professional Reports
Export to PDF, SARIF, JSON, HTML with evidence and remediation
BRS-KB Integration
Thousands of payloads from BRS-KB knowledge base via API
Installation
Quick Start
Basic Scan
brs-xss scan https://target.tld
Deep Scan with DOM
brs-xss scan https://target.tld --deep
Knowledge Base
brs-xss kb info
brs-xss kb list
brs-xss kb show html_content
Legal & Ethics
Authorized Use Only
Use this tool only for authorized security testing with explicit written permission from system owners.
Responsible Disclosure
Report vulnerabilities to affected parties before public disclosure. Follow coordinated disclosure practices.
No Warranty
This tool is provided "as is" without warranty. Users are solely responsible for compliance with laws.
Unauthorized access to computer systems is illegal. Misuse of this tool may result in criminal prosecution.