akto-api-security / tests-library
Community generated list of API security tests to find OWASP top10, HackerOne top 10 vulnerabilities
☆37Updated this week
Alternatives and similar repositories for tests-library
Users that are interested in tests-library are comparing it to the libraries listed below
Sorting:
- A Burp Suite extension for CSRF proof of concepts.☆51Updated 2 years ago
- A tool that automates the search for IDOR vulnerabilities in web apps and APIs☆58Updated 4 years ago
- Create your own recon & vulnerability scanner with Trickest and GitHub☆49Updated last year
- swagroutes is a command-line tool that extracts and lists API routes from Swagger files in YAML or JSON format.☆58Updated 2 years ago
- Regex patterns for manual application source code review☆27Updated 4 years ago
- 🔭 Collection of regexp pattern for security passive scanning☆114Updated 2 years ago
- Build OpenApi specs for your APIs from Burp's traffic using Levo.ai. Also detect the PII in your APIs.☆30Updated last month
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆59Updated this week
- ☆80Updated last year
- ☆59Updated 10 months ago
- Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops☆42Updated last year
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Updated 8 months ago
- Running nuclei Continuously☆55Updated 2 years ago
- List all public repositories for (valid) GitHub usernames☆73Updated last year
- A list of threat sinks used in the manual security source code review for application security☆71Updated 2 years ago
- security.txt collection of most popular world-wide domains☆54Updated last year
- ☆78Updated last year
- Script to test open Akamai ARL vulnerability.☆71Updated 3 years ago
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- HTTP parameter discovery suite.☆63Updated 4 years ago
- Tool for testing reflections in the HTTP responses☆60Updated last year
- IIS shortname scanner + bruteforce☆52Updated last year
- ☆87Updated 3 years ago
- Community Workflow for the Osmedeus Engine that describes basic reconnaissance methodology for you to build your own☆71Updated last year
- A Burp Suite extension to extract datas from source code while browsing.☆158Updated last year
- Detects request smuggling via HTTP/2 downgrades.☆92Updated 2 years ago
- BBSSRF - Bug Bounty SSRF is a powerful tool to check SSRF OOB connection☆38Updated 2 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆29Updated last year
- Alternative to XSS Hunter for blind XSS.☆51Updated 2 years ago