
APIHarvester
The one shot API attacker tool - finds the API url from the given root simulate the automated attacks

The one shot API attacker tool - finds the API url from the given root simulate the automated attacks

Burp Suite extension that extends active and passive scanning with checks for host header attacks, XXE, expression language injection, shellshock and…

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

Martian is a library for building custom HTTP/S proxies

GraphQL automated security testing toolkit

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

REST/JSON API to the Burp Suite security tool.

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

A modern vulnerable web app

Web app authorisation coverage scanning

Http request smuggling vulnerability scanner

Python API security testing tool from OpenStack Security Group

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

Hackable HTTP proxy for resiliency testing and simulated network conditions

Burp Suite extension that uses AI-generated regex strike rules to detect IDOR and access-control flaws, then scans proxy history to find similar…

An on-path blackbox network traffic security testing tool

Sample Burp Suite extensions demonstrating the Montoya API, covering HTTP and proxy handlers, custom scan checks, Intruder payloads, WebSocket…

Burp Suite extension that extends active and passive scanning with checks for host header attacks, XXE, code injection, and known CVEs like…