
OFFAT
Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

Zed Attack Proxy Scripts for finding CVEs and Secrets.

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

BoB Web Application Security Project

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Hash-based malware scanner for incident response. Scans files recursively using known malware hashes, supports multithreading, extension filtering,…

End to End testing of Web, API, Cloud, Events and Security

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

A Security Tool for Enumerating WebSockets

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…