
Pegasus-Pentest-Arsenal
A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

A fast WordPress plugin enumeration tool

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

WEB SERVICE SECURITY ASSESSMENT TOOL

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.