
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Automatic SQL injection and database takeover tool

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Simple JMX RMI scanning tool

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and…

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

☸The first ever dependency-aware GraphQL API testing tool!

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

A fast, simple, recursive content discovery tool written in Rust.

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses