microsoft / rest-api-fuzz-testingLinks
REST API Fuzz Testing (RAFT): Source code for self-hosted service developed for Azure, including the API, orchestration engine, and default set of security tools (including MSR's RESTler), that enables developers to embed security tooling into their CI/CD workflows
☆265Updated 3 years ago
Alternatives and similar repositories for rest-api-fuzz-testing
Users that are interested in rest-api-fuzz-testing are comparing it to the libraries listed below
Sorting:
- A pytest-inspired, DAST framework, capable of identifying vulnerabilities in a distributed, micro-service ecosystem through chaos enginee…☆227Updated last year
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆157Updated last year
- SARIF Microsoft Visual Studio Code extension☆127Updated 3 weeks ago
- Collection of tools for analyzing open source packages.☆353Updated 2 weeks ago
- A React-based component for viewing SARIF files.☆100Updated last year
- Microsoft Threat Modeling Template files☆200Updated 3 years ago
- ClusterFuzzLite - Simple continuous fuzzing that runs in CI.☆512Updated 3 weeks ago
- Java Observability Toolkit☆62Updated last year
- Fuzz test your application using your OpenAPI or Swagger API definition without coding☆464Updated 9 months ago
- Prepackaged and precompiled github codeql container for rapid analysis, deployment and development.☆122Updated 2 years ago
- DevSkim is a set of IDE plugins, language analyzers, and rules that provide security "linting" capabilities.☆969Updated 2 weeks ago
- threatspec - continuous threat modeling, through code☆374Updated 4 years ago
- Security Crawl Maze is a comprehensive testbed for web security crawlers. It contains pages representing many ways in which one can link …☆164Updated 3 weeks ago
- A tool to automatically build a dependency graph and Software Bill of Materials (SBOM) for packages and arbitrary source code repositorie…☆378Updated this week
- User-friendly documentation for the SARIF file format.☆333Updated 2 years ago
- OWASP IoT Security Verification Standard (ISVS)☆148Updated 2 months ago
- Original workshops and staging area for new ones☆16Updated 5 months ago
- Security scanning & static analysis tool☆93Updated last year
- OpenSSF Security Tooling Working Group☆320Updated 5 months ago
- Finding potential software vulnerabilities from git commit messages☆418Updated 2 years ago
- ☆252Updated 5 years ago
- OpenAPI 2.0 (Swagger) fuzzer written in python. Basically TnT for your API.☆111Updated 3 years ago
- The DevSecOps toolset for REST APIs☆277Updated 2 years ago
- Software Component Verification Standard (SCVS)☆152Updated 8 months ago
- ☆74Updated 5 years ago
- A cross-platform browser fuzzing framework☆314Updated this week
- Open Source Software Secure Supply Chain Framework☆238Updated 3 years ago
- .NET code and supporting files for working with the 'Static Analysis Results Interchange Format' (SARIF, see https://github.com/oasis-tcs…☆208Updated 2 weeks ago
- Action to detect if a secret is initially detected in a pull request☆18Updated last week
- A Node.js vulnerability finding tool.☆96Updated 4 months ago