
api-scanner-docker
Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Automated OAuth signature generation and request tampering tool for testing OAuth-protected APIs. Supports GET, POST, PUT, DELETE, proxy…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Batch detection tool for Spring Cloud Gateway Actuator API SpEL injection (CVE-2022-22947) enabling command execution, with concurrent scanning and…

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

☸The first ever dependency-aware GraphQL API testing tool!

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac 🎉 Open an issue here to…

REST/JSON API to the Burp Suite security tool.

An on-path blackbox network traffic security testing tool

Python API security testing tool from OpenStack Security Group

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and…

Metlo is an open-source API security platform.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Rust-powered HTTP Request Smuggling Scanner.