#1Tools for assessing the security of REST, SOAP, and GraphQL APIs.
Kitploit recommended

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Automatic SQL injection and database takeover tool

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Fast web fuzzer written in Go

Web path scanner

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.

A next-generation crawling and spidering framework.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A fast, simple, recursive content discovery tool written in Rust.

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…