
api-scanner-docker
Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Some good resources for getting started with application security

MAPS cloud scanner and response parser for Microsoft Defender research.

An API hooking framework for intercepting and monitoring Windows applications

WEB SERVICE SECURITY ASSESSMENT TOOL

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Collaborative application security testing between humans and agents via CLI and MCP

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

The AI toolkit for building reliable browser automations

⚡️ Multiple target ZAP Scanning

Radamsa fuzzer extension for Burp Suite

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Martian is a library for building custom HTTP/S proxies

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

PyJFuzz - Python JSON Fuzzer
