
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

⚡️ Multiple target ZAP Scanning

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

End to End testing of Web, API, Cloud, Events and Security

This extension integrates popular CAPTCHA solution services into BurpSuite to process different types of CAPTCHAs without manual intervention.

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…


An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…