
SwaggerSpy
Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…

NebulousAD automated credential auditing tool.

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

Automated, policy-driven data retention and deletion system with immutable audit trails, RBAC/ABAC, multi-jurisdiction compliance, and AI/ML…

Automated data flow platform for processing and distributing data with built-in provenance tracking, secure configuration, and scalable pipeline…

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

A script that automatically submits files to Hybrid Analysis (API)

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

cMCP: Confidential MCP Gateway. Hardware-attested policy enforcement for MCP tool calls.

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

A command-line tool to check if passwords have been exposed in data breaches using the Have I Been Pwned (HIBP) API.