
syntribos
Python API security testing tool from OpenStack Security Group

AI-powered bug bounty hunting toolkit that works with or without subscription.

Automated Security Testing For REST API's

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Metlo is an open-source API security platform.

Tests your WAF with +160 payloads

Official Elastic Skills

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Rust-powered HTTP Request Smuggling Scanner.

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Automated testing suite with live traffic record and replay

A program for testing WAF functionality

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

MAPS cloud scanner and response parser for Microsoft Defender research.

RESTful API wrapping Nmap for automated network scanning, port detection, service enumeration, and vulnerability analysis with optional AI-powered…

CyberArk Security Audit

HTTP Proxy Analysis for reverse engineering protocol communication