A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Security vulnerabilities within your own API Security CTF.
β334Jun 10, 2026Updated last month
Alternatives and similar repositories for capital
Users that are interested in capital are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β143May 3, 2026Updated 2 months ago
- Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practisβ¦β1,696May 24, 2025Updated last year
- completely ridiculous API (crAPI)β1,548May 14, 2026Updated 2 months ago
- An extension to use Semgrep inside Burp Suite.β90May 23, 2025Updated last year
- Vulnerable REST API with OWASP top 10 vulnerabilities for security testingβ1,277Apr 7, 2026Updated 3 months ago
- Managed Kubernetes at scale on DigitalOcean β’ AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Proactive, Open source API security β API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom teβ¦β1,493Updated this week
- Vulnerable app with examples showing how to not use secretsβ1,451Updated this week
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalationβ113Feb 16, 2024Updated 2 years ago
- A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.β237Jan 10, 2024Updated 2 years ago
- Extract URLs, paths, secrets, and other interesting bits from JavaScriptβ1,867May 22, 2024Updated 2 years ago
- Black box fuzzer for web applicationsβ438Jul 20, 2025Updated last year
- Burp Suite Certified Practitioner Exam Studyβ1,444Mar 12, 2026Updated 4 months ago
- β17May 16, 2022Updated 4 years ago
- AWSGoat : A Damn Vulnerable AWS Infrastructureβ2,038May 20, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.β1,345Jan 10, 2025Updated last year
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secretsβ1,576Mar 8, 2026Updated 4 months ago
- Secrets scanner that understands codeβ192Nov 2, 2023Updated 2 years ago
- β247Jun 23, 2026Updated 3 weeks ago
- Kraken, a modular multi-language webshell coded by @secu_x11β555Feb 10, 2024Updated 2 years ago
- Automating situational awareness for cloud penetration tests.β2,530May 26, 2026Updated last month
- 2022 CTF public releaseβ23Jun 15, 2022Updated 4 years ago
- Awesome secure by default libraries to help you eliminate bug classes!β710Dec 6, 2025Updated 7 months ago
- REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applicationsβ1,366Aug 7, 2025Updated 11 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer β’ AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assetsβ874Mar 28, 2025Updated last year
- Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.β1,594Aug 6, 2025Updated 11 months ago
- Unleash the power of cloudβ820Nov 19, 2024Updated last year
- Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!β1,089Mar 24, 2026Updated 3 months ago
- Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and gitβ155Jun 17, 2026Updated last month
- π§° Multi Tool Kubernetes Pentest Imageβ262Mar 30, 2026Updated 3 months ago
- A very simple AEM detector written in rust.π¦β20Jun 27, 2023Updated 3 years ago
- A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.β335Jun 5, 2026Updated last month
- A GraphQL enumeration and extraction toolβ134Jan 29, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer β’ AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Kubernetes exploitation toolβ363Feb 25, 2026Updated 4 months ago
- A collection of Active Directory, phishing, mobile technology, system, service, web application, and wireless technology weaknesses that β¦β257Aug 31, 2022Updated 3 years ago
- AzureGoat : A Damn Vulnerable Azure Infrastructureβ954Oct 30, 2024Updated last year
- GCP GOAT is the vulnerable application for learn the GCP Securityβ71May 20, 2026Updated 2 months ago
- β15Jul 17, 2024Updated 2 years ago
- β106Jan 3, 2023Updated 3 years ago
- β384May 17, 2023Updated 3 years ago