
auth_analyzer
Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Rust-powered HTTP Request Smuggling Scanner.

A rapid HTTP downgrade smuggling scanner written in Go.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Damn Vulnerable C# Application (API)

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

⚡️ Multiple target ZAP Scanning

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

The collaborative web app pentest suite

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities