
OFFAT
Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

OWASP Serverless Top 10

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Node.js SDK for capturing and replaying API calls made to/from your service

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

MAPS cloud scanner and response parser for Microsoft Defender research.

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

Hermes Proxy - HTTP Traffic Analyzer

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Application scanning component of purpleteam

Type-safe HTTP client library for Android and Java, enabling REST API communication with annotation-based request configuration and converter support.

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Demonstrates a critical GraphQL batching alias-confusion SQL injection (CVE-2026-5432) with a vulnerable Node.js server and Python exploit for…

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.