
graphw00f
GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Threat Hunting tool about Sysmon and graphs

WEB SERVICE SECURITY ASSESSMENT TOOL

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Enterprise WAF evaluation tool that sends 90 real attack payloads across 6 suites (OWASP, API, bypass, rate limiting) and generates compliance-ready…

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

☸The first ever dependency-aware GraphQL API testing tool!

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac 🎉 Open an issue here to…

Burp Suite extension for automated GraphQL security testing with schema introspection, vulnerability scanning, batch query attacks, and engine…

Burp Suite extension for automated hidden parameter discovery using line-by-line response comparison, multi-threaded wordlists, and automatic issue…

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…