akto-api-security / tests-library
Community generated list of API security tests to find OWASP top10, HackerOne top 10 vulnerabilities
☆33Updated this week
Related projects ⓘ
Alternatives and complementary repositories for tests-library
- Execute Trickest workflows right from your terminal☆85Updated last month
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- Create your own recon & vulnerability scanner with Trickest and GitHub☆49Updated last year
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆51Updated 2 months ago
- List all public repositories for (valid) GitHub usernames☆68Updated last year
- A set of open-source community scripts☆60Updated last month
- Mine URLs from Browser's Heap Snapshot for fun and profit☆63Updated last year
- Chrome extension for automating CSPT discovery☆49Updated last month
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆52Updated this week
- Security Advisories☆32Updated last year
- Monitoring the Cloud Landscape☆74Updated this week
- Regex patterns for manual application source code review☆25Updated 3 years ago
- An extension to use Semgrep inside Burp Suite.☆88Updated last year
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆39Updated 5 months ago
- Script to test open Akamai ARL vulnerability.☆70Updated 3 years ago
- ☆56Updated 8 months ago
- This repository hosts several snippets and file related to the BsidesLV 2024 talk about Shadow and Zombie APIs by me☆17Updated 3 months ago
- 🔭 Collection of regexp pattern for security passive scanning☆114Updated last year
- Finds graphql queries in javascript files☆57Updated 6 months ago
- A Firefox Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆22Updated 7 months ago
- EvenBetterExtensions allows you to quicky install and keep updated Caido extensions.☆23Updated last month
- swagroutes is a command-line tool that extracts and lists API routes from Swagger files in YAML or JSON format.☆54Updated last year
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆77Updated last year
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆86Updated 9 months ago
- OWASP Foundation Web Respository☆23Updated 5 months ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆27Updated last year
- Deploy a SOCKS5 proxy in DigitalOcean and autoconfigure the Burp proxy settings to route all traffic through the droplet☆53Updated 3 weeks ago
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆54Updated last year
- Fetch Javascript sourcemaps, bounty hunter style☆37Updated last year