
nogotofail
An on-path blackbox network traffic security testing tool

An on-path blackbox network traffic security testing tool

Hidden parameters discovery suite

OAuth Request Crafter

REST/JSON API to the Burp Suite security tool.

WEB SERVICE SECURITY ASSESSMENT TOOL

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Comprehensive vulnerability detection tool for n8n workflow automation instances. Detects the critical CVE-2026-21858 vulnerability (CVSS 10.0)…

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

MAPS cloud scanner and response parser for Microsoft Defender research.

An API hooking framework for intercepting and monitoring Windows applications