
katana
A next-generation crawling and spidering framework.

A next-generation crawling and spidering framework.

A fast, simple, recursive content discovery tool written in Rust.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Go client to communicate with Chaos DB API.

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

A fast WordPress plugin enumeration tool

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Metlo is an open-source API security platform.

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…


Burp Plugin to decrypt AES encrypted traffic on the fly

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

End to End testing of Web, API, Cloud, Events and Security