BRS-XSS

XSS Vulnerability Scanner

For authorized security research, penetration testing & education

--- Payloads
--- Contexts
--- WAF Bypasses
--- GitHub Stars

Features

Context-Aware Payloads

HTML, JavaScript, CSS, URI, SVG, XML contexts with intelligent payload selection

WAF Evasion

Bypass Cloudflare, Akamai, AWS WAF, Imperva, ModSecurity, and more

DOM Analysis

Full browser-based DOM XSS detection via Playwright headless browser

Intelligent Classification

Automatic XSS type detection and severity scoring with CVSS

Professional Reports

Export to PDF, SARIF, JSON, HTML with evidence and remediation

BRS-KB Integration

Thousands of payloads from BRS-KB knowledge base via API

Installation

PyPI

pip install brs-xss

GitHub

pip install git+https://github.com/EPTLLC/BRS-XSS.git

Docker

docker pull ghcr.io/eptllc/brs-xss:latest

Quick Start

Basic Scan

brs-xss scan https://target.tld

Deep Scan with DOM

brs-xss scan https://target.tld --deep

Knowledge Base

brs-xss kb info
brs-xss kb list
brs-xss kb show html_content

BRS-KB Knowledge Base

BRS-XSS is powered by BRS-KB - open-source XSS knowledge base

v4.0.0
--- Payloads
--- Contexts
--- WAF Bypasses
No Rate Limits