
Mobile-Security-Framework-MobSF
Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

An intentionally designed broken web application based on REST API.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Application scanning component of purpleteam

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Tests your WAF with +160 payloads

Server scanning component of purpleteam

a Damn Vulnerable Serverless Application