#1API testing, fuzzing, schema validation, authentication testing, and gateway security tools.
Kitploit recommended

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
The Secure CommsOS™ for mission-critical operations

Open Source Identity and Access Management For Modern Applications and Services

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Automatic SQL injection and database takeover tool

The Symfony PHP framework

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

eBPF-based Networking, Security, and Observability

The easiest, and most secure way to access and protect all of your infrastructure.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Industrial-grade C++ RPC framework for building high-performance distributed systems, supporting multiple protocols (HTTP, gRPC, Redis, Thrift) with…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Authorization library enforcing ACL, RBAC, ABAC, and custom access-control models with RESTful matching and policy management APIs for applications…

Fast web fuzzer written in Go

Web path scanner

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…