
api_wordlist
A wordlist of API names for web application assessments

A wordlist of API names for web application assessments

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Automated HTTP Request Repeating With Burp Suite

A coverage-guided REST API fuzzer developed on top of LibAFL

Discover hidden parameters in Caido

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

SAML2 Burp Extension

Radamsa fuzzer extension for Burp Suite

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

MAPS cloud scanner and response parser for Microsoft Defender research.

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.