Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
cats — Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no coding effort, covering boundary and security scenarios. | Kitploit
Herramientas/GitHubGitHub/endava/cats
Vulnerability ScannersAPI Security TestingWeb SecurityFuzzing
GitHubendava/cats

cats

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no coding effort, covering boundary and security scenarios.

Ver Repositorio
1.4k9035hace 9h 33mRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

CATS logo

CI Commits

License Java Version GraalVM Quality Gate Status Coverage Bugs Code Smells

CATS documentation is available at https://endava.github.io/cats/

REST API fuzzer and negative testing tool. Run thousands of self-healing API tests within minutes with no coding effort!

  • Comprehensive: tests are generated automatically based on a large number scenarios and cover every field and header
  • Intelligent: tests are generated based on data types and constraints; each Fuzzer has specific expectations depending on the scenario under test
  • Highly Configurable: high amount of customization: you can filter specific Fuzzers, HTTP response codes, HTTP methods, request paths, provide business context and a lot more
  • Self-Healing: as tests are generated, any OpenAPI spec change is picked up automatically
  • Simple to Learn: flat learning curve, with intuitive configuration and syntax
  • Fast: automatic process for write, run and report tests which covers thousands of scenarios within minutes

Short on time? Check out the 1-minute Quick Start Guide!

Overview

By using a simple and minimal syntax, with a flat learning curve, CATS (Contract API Testing and Security) enables you to generate thousands of API tests within minutes with no coding effort. All tests are generated, run and reported automatically based on a pre-defined set of 100+ Fuzzers. The Fuzzers cover a wide range of boundary testing and negative scenarios from fully random large Unicode values to well crafted, context dependant values based on the request data types and constraints. Even more, you can leverage the fact that CATS generates request payloads dynamically and write simple end-to-end functional tests.

HTML Report

CATS

Command Line

CATS

Terminal interface

Use --tui on a normal fuzzing command to follow execution and inspect results without leaving the terminal:

cats --contract openapi.yml --server http://localhost:8080 --tui

The overview shows Paths, Run configuration, Response time, HTTP Response Codes, Success/Warnings/Errors, and Fuzzers run using the same terminology as the CLI and HTML report. The fuzzer table uses all available terminal rows; use j/k or Page Up/Page Down to browse it when the complete list does not fit. Press 2 for Execution Details, 3 for the Execution summary and Quality gate result, 4 for Execution Details by Result Reason, 5 for Paths included, or 6 for executed tests sorted by Response Time. Result Reason and Path rows open their matching tests with Enter.

Use the arrow keys or j/k to select a test, and press Enter to inspect its request, response, result, trace, and replay command in a full-screen detail view. Press / in the test list to search test IDs, fuzzers, paths, scenarios, result reasons, methods, results, and response codes. a, e, w, s, and i filter all, error, warning, successful, and skipped results. Esc first clears an active search and otherwise returns to the previous screen; 1 opens the overview.

Press q to leave the interface. During an active run this requests cancellation, finishes the current test where possible, preserves results already written, and exits with status 130. After execution has finished, q exits normally.

The TUI requires an interactive terminal of at least 80 columns by 24 rows and cannot be combined with --dryRun. It is available for OpenAPI-backed fuzzing commands; the standalone template command continues to use normal CLI output. The TUI retains the most recent 10,000 test details by default; use --tuiMaxResults to choose a different positive limit. Aggregate statistics continue to cover the complete run when older details are discarded.

Tutorials on how to use CATS

This is a list of articles with step-by-step guides on how to use CATS:

  • Testing the GitHub API with CATS
  • How to write self-healing functional tests with no coding effort

Some bugs found by CATS

  • https://github.com/hashicorp/vault/issues/13274 | https://github.com/hashicorp/vault/issues/13273
  • https://github.com/hashicorp/vault/issues/13225 | https://github.com/hashicorp/vault/issues/13232
  • https://github.com/go-gitea/gitea/issues/19397 | https://github.com/go-gitea/gitea/issues/19398
  • https://github.com/go-gitea/gitea/issues/19399

Installation

Homebrew

> brew tap endava/tap
> brew install cats

Manual

CATS is bundled both as an executable JAR or a native binary. The native binaries do not need Java installed.

After downloading your OS native binary, you can add it to PATH so that you can execute it as any other command line tool:

sudo cp cats /usr/local/bin/cats

You can also get autocomplete by downloading the cats_autocomplete script and do:

source cats_autocomplete

To get persistent autocomplete, add the above line in .zshrc or .bashrc, but make sure you put the fully qualified path for the cats_autocomplete script.

You can also check the cats_autocomplete source for alternative setup.

There is no native binary for Windows, but you can use the uberjar version. This requires Java 25+ to be installed.

You can run it as java -jar cats.jar.

Head to the releases page to download the latest version: https://github.com/Endava/cats/releases.

TLS

CATS verifies server certificates and hostnames by default. For trusted test environments using self-signed certificates, verification can be disabled explicitly with --insecure.

For mutual TLS, use --sslKeystore, --sslKeystorePwd and --sslKeyPwd. If --sslKeyPwd is omitted, CATS uses the keystore password for the private key.

Secrets and replay

Descargar herramienta