nicholasaleks / graphql-threat-matrixLinks
GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations
☆340Updated 6 months ago
Alternatives and similar repositories for graphql-threat-matrix
Users that are interested in graphql-threat-matrix are comparing it to the libraries listed below
Sorting:
- graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology…☆796Updated 7 months ago
- Security Auditor Utility for GraphQL APIs☆588Updated 2 months ago
- CrackQL is a GraphQL password brute-force and fuzzing utility.☆343Updated last year
- GraphQL automated security testing toolkit☆332Updated last year
- The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.☆456Updated 2 years ago
- GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations☆404Updated 3 years ago
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆205Updated last year
- Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable …☆749Updated 2 years ago
- Awesome information for WebSockets security research☆296Updated 4 years ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆713Updated last week
- GQLSpection - parses GraphQL introspection schema and generates possible queries☆98Updated 10 months ago
- ☆182Updated last year
- Bambdas collection for Burp Suite Professional and Community.☆484Updated last week
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆327Updated 6 months ago
- A Firefox Web Extension to improve the discovery of DOM XSS.☆286Updated last year
- EvenBetter is a frontend Caido plugin that makes the Caido experience even better 😎☆161Updated this week
- ☆154Updated 2 years ago
- Automated learning of regexes for DNS discovery☆387Updated 2 years ago
- CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).☆151Updated 9 months ago
- 🕸️ Blazing fast GraphQL endpoints finder using subdomain enumeration, scripts analysis and bruteforce. 🕸️☆227Updated 2 years ago
- Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.☆560Updated 10 months ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆282Updated 4 months ago
- ☆520Updated last year
- Fast and customizable vulnerability scanner For JIRA written in Python☆345Updated last year
- ☆383Updated 2 years ago
- Rust-based high performance domain permutation generator.☆296Updated 2 years ago
- Gotator is a tool to generate DNS wordlists through permutations.☆503Updated 3 years ago
- ☆533Updated 2 months ago
- Burp extension to create target specific and tailored wordlist from burp history.☆255Updated 4 years ago
- Unofficial documentation for the great tool Param Miner☆185Updated 3 years ago