Yelp / fuzz-lightyear
A pytest-inspired, DAST framework, capable of identifying vulnerabilities in a distributed, micro-service ecosystem through chaos engineering testing and stateful, Swagger fuzzing.
☆205Updated 4 months ago
Related projects: ⓘ
- OpenAPI 2.0 (Swagger) fuzzer written in python. Basically TnT for your API.☆109Updated last year
- Generic SAST Library☆123Updated 2 months ago
- Fuzz test your application using your OpenAPI or Swagger API definition without coding☆417Updated 2 months ago
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆145Updated 4 years ago
- API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities☆384Updated 7 years ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆138Updated 6 months ago
- REST API Fuzz Testing (RAFT): Source code for self-hosted service developed for Azure, including the API, orchestration engine, and defau…☆262Updated 2 years ago
- A starter secure code review checklist☆175Updated 5 years ago
- Automate security tests using Burp Suite.☆222Updated 3 months ago
- Small Python library that makes it easy to exploit race conditions in web apps with Requests.☆151Updated last year
- A cross-platform browser fuzzing framework☆300Updated this week
- A Node.js vulnerability finding tool.☆95Updated 3 years ago
- Finding potential software vulnerabilities from git commit messages☆390Updated 11 months ago
- threatspec - continuous threat modeling, through code