
Arjun
HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

A wordlist of API names for web application assessments

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

SAML2 Burp Extension

PyJFuzz - Python JSON Fuzzer

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

A rapid HTTP downgrade smuggling scanner written in Go.

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Python API security testing tool from OpenStack Security Group

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

pysap is an open source Python library that provides modules for crafting and sending packets using SAP's NI, Diag, Enqueue, Router, MS, SNC, IGS,…