
OFFAT
Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Python library built on Scapy for crafting, dissecting, and sending packets over SAP proprietary protocols (NI, Diag, RFC, HDB). Includes client,…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Automated security scanner for websites built with JavaScript module bundlers like Webpack. Extracts APIs from bundled JS and tests for SQL…

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

A wordlist of API names for web application assessments

Burp Suite extension for testing SAML infrastructures. Manipulate SAML messages, perform signature spoofing, XSW, XXE, and XSLT attacks, and manage…

Extensible Python framework for fuzzing JSON inputs across REST APIs, browsers, and executables, with built-in HTTP/HTTPS servers, process crash…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

A rapid HTTP downgrade smuggling scanner written in Go.

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

MAPS cloud scanner and response parser for Microsoft Defender research.

Discovers hidden parameters by fuzzing URL query strings, request bodies, and headers with custom wordlists from within Caido during web security…