akto-api-security / tests-libraryLinks
Community generated list of API security tests to find OWASP top10, HackerOne top 10 vulnerabilities
☆38Updated this week
Alternatives and similar repositories for tests-library
Users that are interested in tests-library are comparing it to the libraries listed below
Sorting:
- Create your own recon & vulnerability scanner with Trickest and GitHub☆49Updated last year
- Execute Trickest workflows right from your terminal☆93Updated this week
- 🔭 Collection of regexp pattern for security passive scanning☆114Updated 2 years ago
- List all public repositories for (valid) GitHub usernames☆74Updated last year
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Updated 10 months ago
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- swagroutes is a command-line tool that extracts and lists API routes from Swagger files in YAML or JSON format.☆60Updated 2 years ago
- Monitoring the Cloud Landscape☆84Updated last week
- A list of threat sinks used in the manual security source code review for application security☆72Updated 2 years ago
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆50Updated 2 years ago
- A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabiliti…☆116Updated last year
- Running nuclei Continuously☆56Updated 2 years ago
- Tool for testing reflections in the HTTP responses☆60Updated 2 years ago
- Community Workflow for the Osmedeus Engine that describes basic reconnaissance methodology for you to build your own☆74Updated last year
- This is a Burp Suite extension that allows users to easily add web addresses to the Burp Suite scope.☆98Updated 6 months ago
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆182Updated 2 years ago
- A very vulnerable implementation of a GraphQL API.☆61Updated 3 years ago
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆68Updated last year
- Regex patterns for manual application source code review☆30Updated 4 years ago
- A tool that automates the search for IDOR vulnerabilities in web apps and APIs☆61Updated 4 years ago
- This is vulnerable microservice written in many language to demonstrating OWASP API Top Security Risk (under development)☆44Updated 2 years ago
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆72Updated last week
- A Burp Suite extension for CSRF proof of concepts.☆52Updated 2 years ago
- OWASP ASVS Security Evaluation Templates with Nuclei☆36Updated last month
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆30Updated 2 years ago
- Checks whether a domain is hosted on a cloud service such as AWS, Azure or CloudFlare☆59Updated 2 years ago
- Recon-Ninja☆88Updated last year
- ☆93Updated last year
- Fetch Javascript sourcemaps, bounty hunter style☆40Updated 2 years ago
- Some contributions in the nuclei-templates repository☆59Updated 3 years ago