assetnote / batchql
GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations
☆378Updated 2 years ago
Alternatives and similar repositories for batchql:
Users that are interested in batchql are comparing it to the libraries listed below
- graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology…☆603Updated 2 months ago
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆189Updated 6 months ago
- GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations☆302Updated last year
- Prototype pollution scanner using headless chrome☆216Updated 2 years ago
- GraphQL automated security testing toolkit☆311Updated last year
- Security Auditor Utility for GraphQL APIs☆425Updated this week
- Rust-based high performance domain permutation generator.☆284Updated last year
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆304Updated 3 months ago
- Unofficial documentation for the great tool Param Miner☆176Updated 2 years ago
- ☆172Updated 3 years ago
- Automated learning of regexes for DNS discovery☆363Updated 2 years ago
- GraphQL security testing tool☆121Updated 2 years ago
- ☆396Updated 3 years ago
- DOM XSS scanner for Single Page Applications☆401Updated 7 months ago
- 🕸️ Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce. 🕸️☆208Updated last year
- Research on GraphQL from an AppSec point of view.☆412Updated last year
- NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.☆371Updated 3 years ago
- CrackQL is a GraphQL password brute-force and fuzzing utility.☆324Updated 6 months ago
- The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.☆352Updated last year
- Security Testing Scripts for JWT☆311Updated 2 years ago
- A simple SSRF-testing sheriff written in Go☆324Updated 3 months ago
- Secret and/or credential patterns used for gf.☆238Updated 2 years ago
- You can read the writeup on this script here☆193Updated 3 years ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆622Updated last year
- Blind XSS Scanner is a tool that can be used to scan for blind XSS vulnerabilities in web applications.☆259Updated 2 months ago
- Vulnerability Scan with Nuclei☆249Updated 3 months ago
- List of fresh DNS resolvers updated daily☆109Updated 2 years ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆265Updated last year
- Burp extension to create target specific and tailored wordlist from burp history.☆234Updated 3 years ago
- ☆149Updated last year