gsmith257-cyber / GraphCrawler
GraphQL automated security testing toolkit
☆302Updated 9 months ago
Related projects ⓘ
Alternatives and complementary repositories for GraphCrawler
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆185Updated 3 months ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆533Updated 11 months ago
- The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.☆329Updated last year
- graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology…☆578Updated last month
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆178Updated 2 years ago
- CrackQL is a GraphQL password brute-force and fuzzing utility.☆315Updated 3 months ago
- Fast and customizable vulnerability scanner For JIRA written in Python☆317Updated 9 months ago
- Unofficial documentation for the great tool Param Miner☆173Updated 2 years ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆295Updated this week
- GQLSpection - parses GraphQL introspection schema and generates possible queries☆71Updated 4 months ago
- A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.☆225Updated 10 months ago
- Vulnerability Scan with Nuclei☆242Updated this week
- GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations☆288Updated 11 months ago
- ☆393Updated 3 years ago
- ☆146Updated last year
- Burp extension to create target specific and tailored wordlist from burp history.☆232Updated 2 years ago
- Get related domains / subdomains by looking at Google Analytics IDs☆228Updated 2 years ago
- Security Auditor Utility for GraphQL APIs☆383Updated 2 months ago
- Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.☆400Updated last month
- Automated learning of regexes for DNS discovery☆358Updated last year
- Prototype pollution scanner using headless chrome☆197Updated 2 years ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆543Updated this week
- ☆358Updated 6 months ago
- Nuclei templates written by us.☆266Updated 3 years ago
- Gotator is a tool to generate DNS wordlists through permutations.☆457Updated 2 years ago
- Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools☆265Updated 4 months ago
- Golang client for querying SecurityTrails API data☆539Updated last year
- EvenBetter is a frontend Caido plugin that makes the Caido experience even better 😎☆134Updated 2 weeks ago
- ☆143Updated last month
- Black box fuzzer for web applications☆404Updated 4 months ago