
graphql-cop
Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…


Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)


Safely test Arista NGFW for information disclosure

Telerik CVE-2017-9248 Vulnerability Scanner

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…



Subdomains analysis and generation tool. Reveal the hidden!

Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across…

A free and open source command-line shell and scripting language designed especially for security testing

Plugin For BurpSuite (Pentester)