
wapiti
Web vulnerability scanner written in Python3

Web vulnerability scanner written in Python3

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

A rapid HTTP downgrade smuggling scanner written in Go.

Apache Real Time Logs Analyzer System

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

find sensitive data leaking from ServiceNow instances.

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

GraphQL automated security testing toolkit

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…