
RatRace
A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Automated OAuth signature generation and request tampering tool for testing OAuth-protected APIs. Supports GET, POST, PUT, DELETE, proxy…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Batch detection tool for Spring Cloud Gateway Actuator API SpEL injection (CVE-2022-22947) enabling command execution, with concurrent scanning and…

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

☸The first ever dependency-aware GraphQL API testing tool!

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac 🎉 Open an issue here to…

REST/JSON API to the Burp Suite security tool.

An on-path blackbox network traffic security testing tool

Python API security testing tool from OpenStack Security Group

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Burp Suite extension for automated GraphQL security testing with schema introspection, vulnerability scanning, batch query attacks, and engine…

Open-source API security platform that inventories endpoints, detects sensitive data, identifies and blocks malicious traffic in real time, and…

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Rust-powered HTTP Request Smuggling Scanner.

Burp Suite extension for automated hidden parameter discovery using line-by-line response comparison, multi-threaded wordlists, and automatic issue…