
XXERipper
Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…
api-security-testingdata-exfiltrationexploitation+9

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Demonstrates a critical GraphQL batching alias-confusion SQL injection (CVE-2026-5432) with a vulnerable Node.js server and Python exploit for…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

In-depth attack surface mapping and asset discovery