
raider
OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

CyberArk Security Audit

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

SAML2 Burp Extension

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

A proxy for net.tcp-based WCF traffic.

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

RumbleTalk Live Group Chat <= 6.1.9 - Missing Authorization via handleRequest

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar