APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and flexible input/output options. Ideal for API security testing.
β367Mar 28, 2025Updated 11 months ago
Alternatives and similar repositories for apidetector
Users that are interested in apidetector are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- πΉ Python project to bruteforce Apache Tomcat manager login with known-default credentialsβ99Mar 12, 2024Updated 2 years ago
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application aβ¦β166Oct 28, 2025Updated 4 months ago
- A Powerful Network Reconnaissance Tool for Security Professionalsβ107Dec 29, 2024Updated last year
- TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines foβ¦β407Dec 22, 2025Updated 3 months ago
- ngrok Collaborator Link β yet another Burp Collaborator alternative for free with ngrok.β113Jan 4, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- A project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectorsβ90Feb 3, 2024Updated 2 years ago
- The Most Advanced Client-Side Prototype Pollution Scannerβ248Updated this week
- hauditor is a tool designed to analyze the security headers returned by a web page.β177Jul 6, 2024Updated last year
- A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issuesβ374Jul 25, 2023Updated 2 years ago
- A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hashβ51Oct 12, 2024Updated last year
- SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applicβ¦β462Mar 28, 2024Updated last year
- Advanced Time-based Blind SQL Injection fuzzer for HTTP Headersβ312Mar 31, 2024Updated last year
- Discover hidden debugging parameters and uncover web application secretsβ246Feb 4, 2026Updated last month
- Identify binaries with Authenticode digital signatures signed to an internal CA/domainβ40Feb 6, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting with the flexibility to host WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Cloudways by DigitalOcean.
- β521Apr 29, 2024Updated last year
- A rapid HTTP downgrade smuggling scanner written in Go.β313May 16, 2024Updated last year
- β544Jun 26, 2024Updated last year
- Simplify your life with leak detection in JavaScript. NipeJS streamlines the use of regex, making it effortless to uncover potential leakβ¦β95Aug 9, 2024Updated last year
- The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The β¦β661Sep 19, 2025Updated 6 months ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.β281Sep 11, 2025Updated 6 months ago
- BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for cβ¦β438Dec 30, 2025Updated 2 months ago
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokensβ164Nov 29, 2024Updated last year
- Repo for hosting rayder workflowsβ63Aug 31, 2023Updated 2 years ago
- DigitalOcean Gradient AI Platform β’ AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- β124Aug 24, 2025Updated 7 months ago
- RepoReaper is an automated tool crafted to meticulously scan and identify exposed .git repositories within specified domains and their suβ¦β35Feb 20, 2024Updated 2 years ago
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secretsβ1,533Mar 8, 2026Updated 2 weeks ago
- Black box fuzzer for web applicationsβ437Jul 20, 2025Updated 8 months ago
- A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzingβ143Jun 27, 2023Updated 2 years ago
- γπγA tool used to hunt down API key leaks in JS files and pagesβ866Mar 12, 2026Updated 2 weeks ago
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive filesβ229Feb 25, 2026Updated last month
- Utility to craft HTML or SVG smuggled files for Red Team engagementsβ247Mar 19, 2024Updated 2 years ago
- uforall is a fast url crawler this tool crawl all URLs number of different sources, alienvault,WayBackMachine,urlscan,commoncrawlβ52Nov 3, 2025Updated 4 months ago
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- β93Apr 29, 2024Updated last year
- Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes through firewalls.β276Jun 16, 2024Updated last year
- Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitatiβ¦β448Jan 25, 2024Updated 2 years ago
- Burp Extension to find potential endpoints, parameters, and generate a custom target wordlistβ1,503Jan 8, 2026Updated 2 months ago
- Clientside vulnerability / reflected xss fuzzerβ149Jul 29, 2023Updated 2 years ago
- NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Reβ¦β1,826Aug 20, 2025Updated 7 months ago
- JavaScript payload and supporting software to be used as XSS payload or post exploitation implant to monitor users as they use the targetβ¦β423Jan 31, 2026Updated last month