gsmith257-cyber / GraphCrawler
GraphQL automated security testing toolkit
☆313Updated last year
Alternatives and similar repositories for GraphCrawler:
Users that are interested in GraphCrawler are comparing it to the libraries listed below
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆191Updated 7 months ago
- graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology…☆611Updated 4 months ago
- The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.☆356Updated last year
- ☆402Updated 3 years ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆629Updated last year
- GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations☆302Updated last year
- GQLSpection - parses GraphQL introspection schema and generates possible queries☆79Updated 3 weeks ago
- CrackQL is a GraphQL password brute-force and fuzzing utility.☆327Updated 7 months ago
- Vulnerability Scan with Nuclei☆250Updated 4 months ago
- Burp extension to create target specific and tailored wordlist from burp history.☆237Updated 3 years ago
- Automated learning of regexes for DNS discovery☆364Updated 2 years ago
- Fast and customizable vulnerability scanner For JIRA written in Python☆317Updated 2 months ago
- De-clutter a list of URLs☆328Updated 4 months ago
- Prototype pollution scanner using headless chrome☆216Updated 2 years ago
- ☆150Updated last year
- 🕸️ Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce. 🕸️☆210Updated last year
- Unofficial documentation for the great tool Param Miner☆178Updated 2 years ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆307Updated 4 months ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆607Updated last week
- Quickly generate context-specific wordlists for content discovery from lists of URLs or paths☆220Updated 2 years ago
- Security Auditor Utility for GraphQL APIs☆436Updated last month
- A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.☆230Updated last year
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆182Updated 2 years ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆623Updated 4 months ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆265Updated 2 years ago
- List of reporting templates I have used since I started doing BBH.☆289Updated 6 months ago
- ☆166Updated 5 months ago
- ☆168Updated last month
- GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations☆381Updated 2 years ago
- openrisk is a tool that generates a risk score based on the results of a Nuclei scan.☆166Updated last month