
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Tools for assessing the security of REST, SOAP, and GraphQL APIs.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Automated Security Testing For REST API's

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)