
Astra
Automated Security Testing For REST API's

Automated Security Testing For REST API's

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

An on-path blackbox network traffic security testing tool

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Web vulnerability scanner written in Python3

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

The AI toolkit for building reliable browser automations

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

Open-source MITM proxy to intercept, inspect, and mock network traffic.