
kong-pwn
Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

A web version of the bash scripts wrote for Check Point CVE-2026-50751 and CVE-2026-50752. This uses a local server to scan and make changes using…

Appspec YML and YAML leaks

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Metlo is an open-source API security platform.

OWASP Honeypot, Automated Deception Framework.

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.


Knocker, a knock based access control service for your homelab

Rewe API reverse engineering in Go
