
wapiti
Web vulnerability scanner written in Python3

Web vulnerability scanner written in Python3

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

The AI toolkit for building reliable browser automations

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Open-source adversary emulation for AI agents and MCP servers.

An strace-like program for the Windows 'native' API

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…