
URL_CHECKER
Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

☸The first ever dependency-aware GraphQL API testing tool!

MAPS cloud scanner and response parser for Microsoft Defender research.

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Hidden parameters discovery suite

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Qualitative TVRA for multi-VLAN enterprise lab scoring stored XSS and EternalBlue via CVSS v3.0 with ZAP, Nessus, and Wireshark evidence.

A Test API for testing the POC against CVE-2022-1388

CVE-2025-55182 testing toolkit with Postman collection, cURL examples, and F5 WAF signature validation for vulnerability assessment and protection…

SAML2 Burp Extension

Hackable HTTP proxy for resiliency testing and simulated network conditions

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…