A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Security vulnerabilities within your own API Security CTF.
β334Jun 10, 2026Updated last month
Alternatives and similar repositories for capital
Users that are interested in capital are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β143May 3, 2026Updated 3 months ago
- Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practisβ¦β1,702May 24, 2025Updated last year
- completely ridiculous API (crAPI)β1,554May 14, 2026Updated 2 months ago
- Vulnerable REST API with OWASP top 10 vulnerabilities for security testingβ1,278Apr 7, 2026Updated 4 months ago
- An extension to use Semgrep inside Burp Suite.β90May 23, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Proactive, Open source API security β API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom teβ¦β1,501Updated this week
- Vulnerable app with examples showing how to not use secretsβ1,455Updated this week
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalationβ113Feb 16, 2024Updated 2 years ago
- A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.β236Jan 10, 2024Updated 2 years ago
- Extract URLs, paths, secrets, and other interesting bits from JavaScriptβ1,887May 22, 2024Updated 2 years ago
- Black box fuzzer for web applicationsβ441Jul 20, 2025Updated last year
- Burp Suite Certified Practitioner Exam Studyβ1,453Mar 12, 2026Updated 4 months ago
- β17May 16, 2022Updated 4 years ago
- vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.β1,349Jan 10, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer β’ AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- AWSGoat : A Damn Vulnerable AWS Infrastructureβ2,040May 20, 2025Updated last year
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secretsβ1,583Mar 8, 2026Updated 5 months ago
- Secrets scanner that understands codeβ193Nov 2, 2023Updated 2 years ago
- Kraken, a modular multi-language webshell coded by @secu_x11β555Feb 10, 2024Updated 2 years ago
- Automating situational awareness for cloud penetration tests.β2,552May 26, 2026Updated 2 months ago
- Awesome secure by default libraries to help you eliminate bug classes!β718Dec 6, 2025Updated 8 months ago
- REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applicationsβ1,368Aug 7, 2025Updated last year
- Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assetsβ879Mar 28, 2025Updated last year
- β245Updated this week
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Unleash the power of cloudβ818Nov 19, 2024Updated last year
- Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!β1,098Updated this week
- A very simple AEM detector written in rust.π¦β20Jun 27, 2023Updated 3 years ago
- π§° Multi Tool Kubernetes Pentest Imageβ262Mar 30, 2026Updated 4 months ago
- A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.β335Jun 5, 2026Updated 2 months ago
- A GraphQL enumeration and extraction toolβ134Jan 29, 2023Updated 3 years ago
- Kubernetes exploitation toolβ362Feb 25, 2026Updated 5 months ago
- A collection of Active Directory, phishing, mobile technology, system, service, web application, and wireless technology weaknesses that β¦β257Aug 31, 2022Updated 3 years ago
- AzureGoat : A Damn Vulnerable Azure Infrastructureβ957Oct 30, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer β’ AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- GCP GOAT is the vulnerable application for learn the GCP Securityβ71May 20, 2026Updated 2 months ago
- Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.β1,605Aug 6, 2025Updated last year
- β15Jul 17, 2024Updated 2 years ago
- β106Jan 3, 2023Updated 3 years ago
- β384May 17, 2023Updated 3 years ago
- CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to β¦β125Apr 10, 2024Updated 2 years ago
- Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.β652Nov 21, 2019Updated 6 years ago