
waf-checker
Tests your WAF with +160 payloads

Tests your WAF with +160 payloads

Official Elastic Skills

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

Open-source adversary emulation for AI agents and MCP servers.

The DevSecOps toolset for REST APIs

WEB SERVICE SECURITY ASSESSMENT TOOL

An strace-like program for the Windows 'native' API


AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

SAML2 Burp Extension

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Hidden parameters discovery suite