
apiscope
An API hooking framework for intercepting and monitoring Windows applications

An API hooking framework for intercepting and monitoring Windows applications

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

WEB SERVICE SECURITY ASSESSMENT TOOL


Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Collaborative application security testing between humans and agents via CLI and MCP

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Stage two containers

⚡️ Multiple target ZAP Scanning

MAPS cloud scanner and response parser for Microsoft Defender research.

This experimetal fuzzer is meant to be used for API in-memory fuzzing.