
pysap
Python library built on Scapy for crafting, dissecting, and sending packets over SAP proprietary protocols (NI, Diag, RFC, HDB). Includes client,…

Python library built on Scapy for crafting, dissecting, and sending packets over SAP proprietary protocols (NI, Diag, RFC, HDB). Includes client,…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Web vulnerability scanner written in Python3

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Discovers hidden parameters by fuzzing URL query strings, request bodies, and headers with custom wordlists from within Caido during web security…

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Burp Suite extension for testing SAML infrastructures. Manipulate SAML messages, perform signature spoofing, XSW, XXE, and XSLT attacks, and manage…

MAPS cloud scanner and response parser for Microsoft Defender research.

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…

A wordlist of API names for web application assessments

Automated API fuzzing and monitoring framework that integrates RESTler and Schemathesis to detect vulnerabilities, with configurable checkers and ELK…

Automated security scanner for websites built with JavaScript module bundlers like Webpack. Extracts APIs from bundled JS and tests for SQL…

A rapid HTTP downgrade smuggling scanner written in Go.

☸The first ever dependency-aware GraphQL API testing tool!