assetnote / batchql
GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations
☆385Updated 2 years ago
Alternatives and similar repositories for batchql:
Users that are interested in batchql are comparing it to the libraries listed below
- graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology…☆624Updated last week
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆191Updated 8 months ago
- GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations☆306Updated last year
- CrackQL is a GraphQL password brute-force and fuzzing utility.☆328Updated 8 months ago
- Prototype pollution scanner using headless chrome☆218Updated 2 years ago
- Unofficial documentation for the great tool Param Miner☆179Updated 2 years ago
- 🐙 Cross-document messaging security research tool powered by https://enso.security☆288Updated last year
- ☆173Updated 3 years ago
- Security Auditor Utility for GraphQL APIs☆450Updated 2 months ago
- DOM XSS scanner for Single Page Applications☆406Updated 3 weeks ago
- NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.☆378Updated 3 years ago
- You can read the writeup on this script here☆193Updated 3 years ago
- Rust-based high performance domain permutation generator.☆286Updated last year
- Automated learning of regexes for DNS discovery☆364Updated 2 years ago
- Security Testing Scripts for JWT☆312Updated 2 years ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆301Updated 2 years ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆173Updated 5 months ago
- Adds a customizable "Send to..."-context-menu to your BurpSuite.☆155Updated 2 years ago
- The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.☆358Updated last year
- ☆151Updated last year
- Client Side Prototype Pollution Scanner☆518Updated 2 years ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆310Updated 5 months ago
- 🕸️ Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce. 🕸️☆215Updated last year
- GoFingerprint is a Go tool for taking a list of target web servers and matching their HTTP responses against a user defined list of fing…☆205Updated last year
- GQLSpection - parses GraphQL introspection schema and generates possible queries☆84Updated last month
- Secret and/or credential patterns used for gf.☆241Updated 2 years ago
- Research on GraphQL from an AppSec point of view.☆414Updated last year
- Continuous monitoring for JavaScript files☆218Updated 5 years ago
- Tool for catching and logging different types of requests.☆220Updated 4 years ago
- ☆405Updated 3 years ago