
faraday_burp
Burp Extension for collaboration in Faraday

Burp Extension for collaboration in Faraday

Lightweight Java 8 web framework for building REST APIs and web applications, with built-in routing, static file serving, and template engine support.

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

A coverage-guided REST API fuzzer developed on top of LibAFL

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

Executable security regression testing for agentic applications and MCP-integrated systems.

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

MCP server for Slither static analysis of Solidity smart contracts

MAPS cloud scanner and response parser for Microsoft Defender research.

An HTTP client specifically developed for security researchers