
graphql-threat-matrix
GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations

GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

Open source tooling to stop ICS phishing (malicious calendar invites)

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

Unified dashboard to monitor, govern, and audit AI agents in real-time. Enforce budgets, detect policy violations, and export compliance reports for…

Proof-of-concept for CVE-2026-59243 demonstrating JWT signature bypass in Apache Airflow FAB Auth Manager's Azure AD OAuth callback due to insecure…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

provides a Firewall Manager API designed to centralize and streamline the management of firewall configurations

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

Temporary WordPress plugin requiring authentication for the Core REST Batch API endpoint to mitigate the wp2shell vulnerability chain…

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode