
GraphCrawler
GraphQL automated security testing toolkit

GraphQL automated security testing toolkit

Application scanning component of purpleteam

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Automatic SQL injection and database takeover tool

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

A next-generation crawling and spidering framework.

A fast, simple, recursive content discovery tool written in Rust.

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Go client to communicate with Chaos DB API.

A fast WordPress plugin enumeration tool

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Metlo is an open-source API security platform.

Tests your WAF with +160 payloads

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…