
WSSAT
WEB SERVICE SECURITY ASSESSMENT TOOL

WEB SERVICE SECURITY ASSESSMENT TOOL

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

a Damn Vulnerable Serverless Application

Zap Extension for collaboration in Faraday

Interactive demo for CVE-2023-45857 (axios XSRF token bypass). Step-by-step guide to reproduce the vulnerability in a controlled dev container…

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

This extension integrates popular CAPTCHA solution services into BurpSuite to process different types of CAPTCHAs without manual intervention.

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…