
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Node.js SDK for capturing and replaying API calls made to/from your service

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Official Elastic Skills

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

WEB SERVICE SECURITY ASSESSMENT TOOL

Http request smuggling vulnerability scanner

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Type-safe HTTP client library for Android and Java, enabling REST API communication with annotation-based request configuration and converter support.

Type-safe HTTP client for Android and Java with annotation-based API binding, converter support, and integration with OkHttp for network…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion