Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pyrasp — Runtime Application Self Protection for Python web servers, serverless functions and MCP servers, detecting attacks, prompt injection and data leaks without signatures. | Kitploit
Tools/GitHubGitHub/rbidou/pyrasp
Defensive ToolsServerless SecurityWeb SecurityCloud SecurityMachine LearningIntrusion DetectionAPI SecurityAI SecurityAnomaly Detection
GitHubrbidou/pyrasp

pyrasp

Runtime Application Self Protection for Python web servers, serverless functions and MCP servers, detecting attacks, prompt injection and data leaks without signatures.

396102 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View RepositoryWebsite
Share

version 0.10.0 A project by ParaCyberBellum @ParaCyberBellum on Twitter

What is PyRASP ?

PyRASP is a Runtime Application Self Protection package for Python-based Web Servers (Flask, FastAPI, Django, aiohttp), Web Gateways (WSGI and ASGI), and Serverless Functions (AWS Lambda, Azure and Google Cloud Functions). It protects against the main attacks web applications are exposed to, from within the application. It is also capable of providing basic telemetry such as cpu and memory usage, as well as requests count. Additionally, PyRASP implements Zero-Trust Application Access for critical applications, ensuring only up-to-date authorized browsers can connect.

PyRASP provides full agentic AI security by protecting MCP servers tools from malicious inputs injections and data leaks (PII and credentials) that would result from unexpected processing. It also defend LLM frontends against malicious prompt injection attempts.

It can operate using a local configuration file or get it from a remote/cloud server. Logs and telemetry (optional) can be sent to remote servers as well, and threats information can be shared across agents.

One specificity of PyRASP relies on the fact that it does not use signatures. Instead it will leverage decoys, thresholds, system and application internals as well as machine learning for detection.

AWS Lambda Functions are no longer supported since version 0.8.3

Documentation

Full documentation
Release Notes
Web Site

Contacts

Renaud Bidou - [email protected]

Download Tool