
crAPI
Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

a Damn Vulnerable Serverless Application

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

Damn Vulnerable C# Application (API)

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Executable security regression testing for agentic applications and MCP-integrated systems.

Automated Security Testing For REST API's

Open-source adversary emulation for AI agents and MCP servers.

The DevSecOps toolset for REST APIs

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

End to End testing of Web, API, Cloud, Events and Security

CLI component of purpleteam

Application scanning component of purpleteam