
sqlmap
Automatic SQL injection and database takeover tool

Automatic SQL injection and database takeover tool

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

A fast, simple, recursive content discovery tool written in Rust.

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Threat Hunting tool about Sysmon and graphs

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.