
crAPI
Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

A collection of awesome resources related AI security

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…