
sqlmap
Automatic SQL injection and database takeover tool

Automatic SQL injection and database takeover tool

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

A fast, simple, recursive content discovery tool written in Rust.

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Threat Hunting tool about Sysmon and graphs

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.