
sj
A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Automatic SQL injection and database takeover tool

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

A fast WordPress plugin enumeration tool

An API hooking framework for intercepting and monitoring Windows applications

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Enterprise WAF evaluation tool that sends 90 real attack payloads across 6 suites (OWASP, API, bypass, rate limiting) and generates compliance-ready…

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

A fast, simple, recursive content discovery tool written in Rust.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Web application firewall testing tool with 344+ attack payloads, auto WAF detection, bypass techniques, and full reconnaissance including DNS,…