


Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Web vulnerability scanner written in Python3

High-speed Burp Suite extension for sending large volumes of HTTP requests with a custom stack, Python-based attack configuration, and advanced…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

LLM powered fuzzing via OSS-Fuzz.

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

Differential testing framework for HTTP implementations

A wordlist of API names for web application assessments

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.