
OFFAT
Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

The AI toolkit for building reliable browser automations

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

The DevSecOps toolset for REST APIs

SSRF plugin for burp Automates SSRF Detection in all of the Request

An strace-like program for the Windows 'native' API

Open-source adversary emulation for AI agents and MCP servers.

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

A rapid HTTP downgrade smuggling scanner written in Go.