An open API service providing repository metadata for many open source software ecosystems.

Topic: "api-security-testing"

akto-api-security/akto

Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure

Language: Java - Size: 325 MB - Last synced at: 12 days ago - Pushed at: 13 days ago - Stars: 1,422 - Forks: 272

nemesida-waf/waf-bypass

Check your WAF before an attacker does

Language: Python - Size: 733 KB - Last synced at: 6 months ago - Pushed at: 6 months ago - Stars: 1,387 - Forks: 172

OWASP/OFFAT

The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.

Language: Python - Size: 12 MB - Last synced at: 4 months ago - Pushed at: 4 months ago - Stars: 645 - Forks: 86

cerberauth/vulnapi

API Security Vulnerability Scanner designed to help you secure your APIs.

Language: Go - Size: 2.93 MB - Last synced at: 15 days ago - Pushed at: 17 days ago - Stars: 228 - Forks: 26

abunuwas/fencer

Automated API security testing

Language: Python - Size: 381 KB - Last synced at: 2 months ago - Pushed at: over 1 year ago - Stars: 88 - Forks: 12

akto-api-security/tests-library

Community generated list of API security tests to find OWASP top10, HackerOne top 10 vulnerabilities

Size: 297 MB - Last synced at: 3 days ago - Pushed at: 7 days ago - Stars: 42 - Forks: 37

Traceableai/ast-action

GitHub action to run Traceable Active Security Testing in GitHub workflows

Size: 28.5 MB - Last synced at: 2 months ago - Pushed at: over 1 year ago - Stars: 4 - Forks: 1

Presh-Cyber/ScriptOcalypse

ScriptOcalypse 🏴‍☠️- Nothing here… just a lot of weird ideas with a chaotic mix of lemonade, boredom, and automation that somehow work.

Language: Python - Size: 84 KB - Last synced at: 2 months ago - Pushed at: 2 months ago - Stars: 3 - Forks: 0

owasp-offat/offat

The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.

Language: Go - Size: 2.78 MB - Last synced at: about 1 year ago - Pushed at: about 1 year ago - Stars: 2 - Forks: 1

Escape-Technologies/escape-rules

A community-driven list of custom Escape rules. Test your API security with rules that automatically adapt for you.

Size: 36.1 KB - Last synced at: 10 months ago - Pushed at: almost 2 years ago - Stars: 2 - Forks: 0

x4r5h/API-Abuse-Detection

Real-time API threat detection and mitigation for FinTech systems

Language: HTML - Size: 20.1 MB - Last synced at: 9 days ago - Pushed at: 10 days ago - Stars: 0 - Forks: 0

mahmud-r-farhan/secure-load-tester

A command-line tool for performance and security testing of Node.js APIs. It supports load testing, CSRF testing, session hijacking testing, JWT validation testing, XSS, SQL Injection, and other security vulnerabilities.

Language: JavaScript - Size: 69.3 KB - Last synced at: about 1 month ago - Pushed at: about 1 month ago - Stars: 0 - Forks: 0

MOHEEB20/Vulna

🤖 Enhance your security with Vulna, an AI-powered penetration testing platform that automates vulnerability verification and smart request filtering.

Language: Python - Size: 1.4 MB - Last synced at: 2 months ago - Pushed at: 2 months ago - Stars: 0 - Forks: 0

bugsmirror/MASST

Bugsmirror MASST (Mobile Application Security Suite and Tools) is a comprehensive platform for end-to-end mobile application security. It offers threat detection tools for static, runtime, dynamic API testing and red teaming; robust app shielding solution for threat mitigation; threat visibility dashboard; & AI powered insight in a single platform.

Size: 6.84 KB - Last synced at: 4 months ago - Pushed at: 4 months ago - Stars: 0 - Forks: 0

darmado/repl

Replace, load and replay Postman collections to Burp, Zap, etc.

Language: Python - Size: 579 KB - Last synced at: 6 months ago - Pushed at: 6 months ago - Stars: 0 - Forks: 1

insomn14/Amba2Pen

Amba2Pen is a Python-based tool designed to streamline the penetration testing process by automating various pentest tasks.

Language: Python - Size: 67.4 KB - Last synced at: 6 months ago - Pushed at: 6 months ago - Stars: 0 - Forks: 0

lunzai/gobrute

A RESTful API brute-forcing tool in Go for ethical hacking practice. **Gobrute** is built for testing login passwords with multithreading, progress tracking, and customizable payloads, ideal for controlled environments like OWASP Juice Shop.

Language: Go - Size: 8.79 KB - Last synced at: 9 months ago - Pushed at: about 1 year ago - Stars: 0 - Forks: 0

0b1000Legs/SpyderByte

An intelligent web-proxy that monitors API requests of a web application and detects API security vulnerabilities automatically.

Language: Python - Size: 42 KB - Last synced at: 3 months ago - Pushed at: about 2 years ago - Stars: 0 - Forks: 0

Related Topics
api-security 10 security 6 owasp-top-10 5 security-testing 5 security-tools 3 api-testing 3 authentication 3 openapi 3 graphql 3 cybersecurity 3 owasp 3 ethical-hacking-tools 2 ethical-hacking 2 api-rest 2 offat 2 rest-api 2 jwt 2 security-scanner 2 api 2 pentesting 2 authorization 2 hacktoberfest 2 hacktoberfest2023 2 dynamic-application-security-testing 1 infosec 1 jailbreak-detection 1 mobile-application-security 1 mobile-application-security-testing 1 redteaming 1 root-detection 1 runtime-application-self-protection 1 runtime-security 1 golang 1 go 1 brute-force 1 cli-tool 1 backend-security-testing 1 threat-monitoring 1 threat-mitigation 1 threat-detection-response 1 threat-dashboard 1 runtime-security-testing 1 static-application-security-testing 1 secure-communication 1 security-automation 1 web-security-tool 1 python-script 1 python-based 1 penetration-testing-tools 1 command-line-tool 1 bug-hunting-tools 1 zaproxy 1 postman-collection 1 burpsuite 1 api-automation-testing 1 threat-intelligence 1 spring4shell 1 slack-webhook 1 redteam 1 osint 1 nvd 1 machine-learning 1 github-action 1 cybersecurity-education 1 cve-monitor 1 automation 1 password-testing 1 password-cracking 1 owasp-juice-shop 1 api-hacking 1 xss 1 waf-testing 1 waf-bypass-tool 1 waf 1 ssti 1 sqli-injection 1 rfi 1 rce 1 python3 1 python 1 path-traversal 1 nosql-injection 1 lfi 1 graphql-injection 1 bypass 1 threat-detection 1 sensitive-data-exposure 1 idor 1 devsecops-pipeline 1 devsecops 1 api-security-posture 1 api-discovery 1 device-integrity 1 app-shielding 1 anti-tampering 1 anti-reverse-engineering 1 owasp-offat 1 hactoberfest 1 vulnerability-detection 1 escape-rules 1