
sj
A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

The AI toolkit for building reliable browser automations

Tests your WAF with +160 payloads

PyJFuzz - Python JSON Fuzzer

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Threat Hunting tool about Sysmon and graphs

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

WEB SERVICE SECURITY ASSESSMENT TOOL

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…


A coverage-guided REST API fuzzer developed on top of LibAFL

CVE-2026-9830 Proof of Concept

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

An strace-like program for the Windows 'native' API

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).