
api_wordlist
A wordlist of API names for web application assessments

A wordlist of API names for web application assessments

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…

Discover hidden parameters in Caido

SAML2 Burp Extension

Radamsa fuzzer extension for Burp Suite

pysap is an open source Python library that provides modules for crafting and sending packets using SAP's NI, Diag, Enqueue, Router, MS, SNC, IGS,…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

MAPS cloud scanner and response parser for Microsoft Defender research.

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Global API Integrity Assessor

☸The first ever dependency-aware GraphQL API testing tool!

PyJFuzz - Python JSON Fuzzer

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

A rapid HTTP downgrade smuggling scanner written in Go.

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.