
automatic-api-attack-tool
Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Threat Hunting tool about Sysmon and graphs

WEB SERVICE SECURITY ASSESSMENT TOOL

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Enterprise WAF evaluation tool that sends 90 real attack payloads across 6 suites (OWASP, API, bypass, rate limiting) and generates compliance-ready…

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Remote PowerShell-based security audit tool for CyberArk PAM platforms. Performs CIS benchmark compliance, CVE checks, blackbox testing, and network…

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…