
yakit
All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows…

Automatic SSTI detection tool with interactive interface

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

High-speed Burp Suite extension for sending large volumes of HTTP requests with a custom stack, Python-based attack configuration, and advanced…

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

Automated web domain reconnaissance and security assessment tool integrating subdomain enumeration, port scanning, vulnerability scanning, and…

Wi-Fi Framework for creating proof-of-concepts, automated experiments, test suites, fuzzers, and more.

exploit CVE-2024-40725 (Apache httpd) with

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

Nuclei template to detect Apache servers vulnerable to CVE-2024-38473

High-performance black-box fuzzer for web applications with built-in payload engine, request verification, tampering, encoding, and advanced…

Software for fuzzing, used on web application pentestings.