
columbus-server
API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…

API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…

Research on GraphQL from an AppSec point of view.

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…

Automatic SQL injection and database takeover tool

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

a Damn Vulnerable Serverless Application

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

An intentionally designed broken web application based on REST API.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Threat Hunting tool about Sysmon and graphs

Academic purposes only. Attack against Salesforce lightning with guest privilege.

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

Burp Extension for collaboration in Faraday