
coraza
Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Application Security Verification Standard

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Open-source access management platform offering single sign-on, adaptive authentication, authorization, and federation for secure access to web,…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Idempotent functions for IBM Security Appliance REST APIs. Currently covering ISAM and ISDS Appliances.

Exploit for CVE-2021-45232 targeting Apache APISIX Dashboard remote code execution vulnerability. Provides proof-of-concept for security testing and…