nicholasaleks / graphql-threat-matrix
GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations
☆302Updated last year
Alternatives and similar repositories for graphql-threat-matrix:
Users that are interested in graphql-threat-matrix are comparing it to the libraries listed below
- graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology…☆611Updated 3 months ago
- Security Auditor Utility for GraphQL APIs☆436Updated last month
- CrackQL is a GraphQL password brute-force and fuzzing utility.☆327Updated 7 months ago
- The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.☆356Updated last year
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆191Updated 7 months ago
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆626Updated last year
- GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations☆381Updated 2 years ago
- GraphQL automated security testing toolkit☆313Updated last year
- ☆166Updated 5 months ago
- Awesome information for WebSockets security research☆261Updated 3 years ago
- GQLSpection - parses GraphQL introspection schema and generates possible queries☆79Updated 2 weeks ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆258Updated last week
- ☆184Updated 4 months ago
- openrisk is a tool that generates a risk score based on the results of a Nuclei scan.☆166Updated last month
- 🕸️ Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce. 🕸️☆210Updated last year
- ☆150Updated last year
- Rust-based high performance domain permutation generator.☆285Updated last year
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆134Updated 3 months ago
- ☆402Updated 3 years ago
- Bambdas collection for Burp Suite Professional and Community.☆249Updated 2 weeks ago
- NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.☆374Updated 3 years ago
- PP-finder Help you find gadget for prototype pollution exploitation☆152Updated 7 months ago
- EvenBetter is a frontend Caido plugin that makes the Caido experience even better 😎☆141Updated this week
- CT Log Scanner☆321Updated last month
- Automated learning of regexes for DNS discovery☆364Updated 2 years ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆607Updated last week
- Vulnerability Scan with Nuclei☆249Updated 4 months ago
- A list of edge cases that occur in bug bounty programs, conversations on how they should be handled. The goal is to standardise the way t…☆229Updated 3 years ago
- Blazing fast GraphQL discovery & fingerprinting toolbox.☆108Updated last year
- jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice☆267Updated 11 months ago