akto-api-security / tests-library
Community generated list of API security tests to find OWASP top10, HackerOne top 10 vulnerabilities
☆35Updated this week
Alternatives and similar repositories for tests-library:
Users that are interested in tests-library are comparing it to the libraries listed below
- Create your own recon & vulnerability scanner with Trickest and GitHub☆49Updated last year
- A Burp Suite extension for CSRF proof of concepts.☆48Updated last year
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆55Updated this week
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆43Updated 8 months ago
- Build OpenApi specs for your APIs from Burp's traffic using Levo.ai. Also detect the PII in your APIs.☆27Updated 7 months ago
- 🔭 Collection of regexp pattern for security passive scanning☆115Updated 2 years ago
- ☆76Updated 9 months ago
- Security Advisories☆32Updated last year
- A list of threat sinks used in the manual security source code review for application security☆70Updated last year
- Regex patterns for manual application source code review☆27Updated 4 years ago
- Summary of almost all paid bounty reports on H1☆40Updated 4 years ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆51Updated 5 months ago
- ☆57Updated last month
- vīlicus is a bug bounty api dashboard☆40Updated last year
- Mine URLs from Browser's Heap Snapshot for fun and profit☆63Updated last year
- Execute Trickest workflows right from your terminal☆87Updated last month
- Tool for testing reflections in the HTTP responses☆60Updated last year
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆28Updated last year
- Modified Nuclei Templates Version to FUZZ Host Header☆49Updated 3 years ago
- A simple plugin to export JS files from one or multiple targets☆40Updated last year
- Enhanced 403 bypass header☆21Updated 2 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- OWASP Foundation Web Respository☆25Updated 8 months ago
- It grep subdomains, email/username, build custom wordlist etc from gau results☆47Updated 2 years ago
- Monitoring the Cloud Landscape☆78Updated 2 months ago
- BBSSRF - Bug Bounty SSRF is a powerful tool to check SSRF OOB connection☆38Updated last year
- Advanced Reconnaissance and Web Application Discovery☆79Updated 3 years ago
- Resolvers updated daily for reconftw☆47Updated 2 years ago
- IIS shortname scanner + bruteforce☆51Updated last year
- An extension to use Semgrep inside Burp Suite.☆88Updated last year