
XXERipper
Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Executable security regression testing for agentic applications and MCP-integrated systems.

Automated Security Testing For REST API's

Open-source adversary emulation for AI agents and MCP servers.

The DevSecOps toolset for REST APIs

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

a Damn Vulnerable Serverless Application

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

End to End testing of Web, API, Cloud, Events and Security

Server scanning component of purpleteam

CLI component of purpleteam