
cherrybomb
CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

PyJFuzz - Python JSON Fuzzer

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

WEB SERVICE SECURITY ASSESSMENT TOOL


⚡️ Multiple target ZAP Scanning

MAPS cloud scanner and response parser for Microsoft Defender research.

Hermes Proxy - HTTP Traffic Analyzer

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

BurpSuite Standard/Private Collaborator Library

An API hooking framework for intercepting and monitoring Windows applications

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

This experimetal fuzzer is meant to be used for API in-memory fuzzing.