API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs
☆119Aug 11, 2026Updated this week
Alternatives and similar repositories for vespasian
Users that are interested in vespasian are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven te…☆73Updated this week
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆86Updated this week
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆176Updated this week
- Simple LLM service identification - translate IP:Port to Ollama, vLLM, LiteLLM, or 60+ other AI services in seconds☆204Updated this week
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian☆322Updated this week
- GitHub Action to alert on security patches before the CVE drops.☆216Updated this week
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆70Nov 27, 2025Updated 8 months ago
- Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra al…☆307Updated this week
- AI-Powered Web Attack Surface Enumeration☆46Feb 5, 2026Updated 6 months ago
- Open-source cloud security reconnaissance framework☆64Updated this week
- High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential v…☆667Aug 4, 2026Updated last week
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆373Updated this week
- A golang-written credential harvesting framework leveraging eBPF for kernel-level monitoring with anti-detection capabilities.☆49Apr 13, 2026Updated 3 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A POC tool for exploring dev-tunnels☆66May 5, 2026Updated 3 months ago
- LLM security testing framework for detecting prompt injection, jailbreaks, and adversarial attacks — 190+ probes, 28 providers, single Go…☆273Updated this week
- GitHub Workflows Insights☆47Jun 27, 2026Updated last month
- Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.☆57Updated this week
- ☆17Apr 16, 2026Updated 3 months ago
- ☆18Sep 9, 2025Updated 11 months ago
- A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.☆26Apr 20, 2026Updated 3 months ago
- Did you contain the compromised identity? notyet☆42Jul 16, 2026Updated 3 weeks ago
- Pentester-focused Docker registry tool to enumerate and pull images☆41Oct 19, 2025Updated 9 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Audit content (pdfs, media files, images) sensitivity on urls☆45Jun 2, 2026Updated 2 months ago
- MCP Attack Surface Detector - Burp plugin to make manual testing of MCP servers easier in Burp Suite☆32Feb 26, 2026Updated 5 months ago
- Notion C2 Profile for Mythic☆48Apr 30, 2026Updated 3 months ago
- Tokenex is a Go library that securely exchanges identity tokens for temporary cloud credentials, with built-in support for AWS, GCP, Azur…☆84Jul 28, 2026Updated 2 weeks ago
- Check your AWS CLI commands for security risks before you run them.☆33Apr 1, 2026Updated 4 months ago
- JamfHound is a python3 project designed to collect and identify attack paths in Jamf Pro tenants based on existing object permissions by …☆134Apr 23, 2026Updated 3 months ago
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆273Mar 30, 2026Updated 4 months ago
- The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2…☆61Jul 23, 2026Updated 2 weeks ago
- This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) an…☆149Feb 4, 2026Updated 6 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps…☆39Updated this week
- Inline proxy for software package registries to provide observability and policy controls to installs.☆51Jun 5, 2026Updated 2 months ago
- Universal Security Visualization library☆17May 31, 2026Updated 2 months ago
- A powerful containerized tool that automatically downloads, extracts, and scans packages from PyPI and npm for embedded secrets, API keys…☆20Jul 25, 2025Updated last year
- MCP security testing framework for evaluating Model Context Protocol server vulnerabilities☆34Feb 17, 2026Updated 5 months ago
- Crawl and analyze JavaScript for secrets, tokens, and API endpoints. A powerful bug bounty tool for automated JS analysis.☆21Apr 3, 2026Updated 4 months ago
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆169May 8, 2026Updated 3 months ago