APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and flexible input/output options. Ideal for API security testing.
β379Mar 28, 2025Updated last year
Alternatives and similar repositories for apidetector
Users that are interested in apidetector are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- πΉ Python project to bruteforce Apache Tomcat manager login with known-default credentialsβ96Mar 12, 2024Updated 2 years ago
- A Powerful Network Reconnaissance Tool for Security Professionalsβ108Dec 29, 2024Updated last year
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application aβ¦β168Oct 28, 2025Updated 10 months ago
- ngrok Collaborator Link β yet another Burp Collaborator alternative for free with ngrok.β116Jan 4, 2024Updated 2 years ago
- TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines foβ¦β426Apr 27, 2026Updated 4 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits β’ AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issuesβ377Jul 25, 2023Updated 3 years ago
- hauditor is a tool designed to analyze the security headers returned by a web page.β177Jul 6, 2024Updated 2 years ago
- Advanced Client-Side Prototype Pollution Scannerβ252Sep 1, 2026Updated last week
- SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applicβ¦β467Mar 28, 2024Updated 2 years ago
- A project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectorsβ91Feb 3, 2024Updated 2 years ago
- Discover hidden debugging parameters and uncover web application secretsβ248Feb 4, 2026Updated 7 months ago
- Advanced Time-based Blind SQL Injection fuzzer for HTTP Headersβ311Mar 31, 2024Updated 2 years ago
- A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hashβ53Oct 12, 2024Updated last year
- β534Apr 29, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Identify binaries with Authenticode digital signatures signed to an internal CA/domainβ41Feb 6, 2024Updated 2 years ago
- β550Jun 26, 2024Updated 2 years ago
- The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The β¦β671Aug 18, 2026Updated 3 weeks ago
- A rapid HTTP downgrade smuggling scanner written in Go.β313May 16, 2024Updated 2 years ago
- BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for cβ¦β444Dec 30, 2025Updated 8 months ago
- Simplify your life with leak detection in JavaScript. NipeJS streamlines the use of regex, making it effortless to uncover potential leakβ¦β95Aug 9, 2024Updated 2 years ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.β280Sep 11, 2025Updated 11 months ago
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secretsβ1,590Mar 8, 2026Updated 5 months ago
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokensβ172Nov 29, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- γπγA tool used to hunt down API key leaks in JS files and pagesβ939Mar 12, 2026Updated 5 months ago
- A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzingβ142Jun 27, 2023Updated 3 years ago
- uforall is a fast url crawler this tool crawl all URLs number of different sources, alienvault,WayBackMachine,urlscan,commoncrawlβ57Nov 3, 2025Updated 10 months ago
- β127Aug 24, 2025Updated last year
- Black box fuzzer for web applicationsβ442Jul 20, 2025Updated last year
- Repo for hosting rayder workflowsβ65Aug 31, 2023Updated 3 years ago
- Clientside vulnerability / reflected xss fuzzerβ150Jul 29, 2023Updated 3 years ago
- Burp Extension to find potential endpoints, parameters, and generate a custom target wordlistβ1,533Jan 8, 2026Updated 7 months ago
- Utility to craft HTML or SVG smuggled files for Red Team engagementsβ247Mar 19, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off β’ AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Reβ¦β1,865Apr 17, 2026Updated 4 months ago
- Go scanner to find web cache poisoning vulnerabilities in a list of URLsβ150Feb 21, 2024Updated 2 years ago
- find dangling domains in a multi cloud environmentβ178Updated this week
- Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitatiβ¦β473Jan 25, 2024Updated 2 years ago
- RepoReaper is an automated tool crafted to meticulously scan and identify exposed .git repositories within specified domains and their suβ¦β35Feb 20, 2024Updated 2 years ago
- fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.β943Aug 24, 2023Updated 3 years ago
- Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes through firewalls.β280Jun 16, 2024Updated 2 years ago