
OFFAT
Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

The AI toolkit for building reliable browser automations

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Tests your WAF with +160 payloads

An strace-like program for the Windows 'native' API

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Open-source adversary emulation for AI agents and MCP servers.

Burp Plugin to decrypt AES encrypted traffic on the fly

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report templates,…

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

Wireshark for MCP. A transparent proxy between your AI client and MCP server. Watch every call live in your terminal, fail CI on what it finds,…

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).