API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs
☆128Sep 16, 2026Updated this week
Alternatives and similar repositories for vespasian
Users that are interested in vespasian are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven te…☆77Sep 11, 2026Updated last week
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆90Sep 11, 2026Updated last week
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆186Updated this week
- Simple LLM service identification - translate IP:Port to Ollama, vLLM, LiteLLM, or 60+ other AI services in seconds☆236Sep 11, 2026Updated last week
- Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian☆358Sep 11, 2026Updated last week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated 2 months ago
- GitHub Action to alert on security patches before the CVE drops.☆218Sep 10, 2026Updated last week
- High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential v…☆705Updated this week
- Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra al…☆325Updated this week
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆72Nov 27, 2025Updated 9 months ago
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆379Updated this week
- AI-Powered Web Attack Surface Enumeration☆55Sep 4, 2026Updated 2 weeks ago
- A golang-written credential harvesting framework leveraging eBPF for kernel-level monitoring with anti-detection capabilities.☆49Apr 13, 2026Updated 5 months ago
- Open-source cloud security reconnaissance framework☆68Updated this week
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- LLM security testing framework for detecting prompt injection, jailbreaks, and adversarial attacks — 190+ probes, 28 providers, single Go…☆290Updated this week
- A POC tool for exploring dev-tunnels☆73May 5, 2026Updated 4 months ago
- ☆24Sep 9, 2025Updated last year
- Pentester-focused Docker registry tool to enumerate and pull images☆41Oct 19, 2025Updated 11 months ago
- GitHub Workflows Insights☆47Jun 27, 2026Updated 2 months ago
- Audit content (pdfs, media files, images) sensitivity on urls☆45Jun 2, 2026Updated 3 months ago
- Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.☆62Updated this week
- Did you contain the compromised identity? notyet☆42Jul 16, 2026Updated 2 months ago
- ☆19Apr 16, 2026Updated 5 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Tokenex is a Go library that securely exchanges identity tokens for temporary cloud credentials, with built-in support for AWS, GCP, Azur…☆86Sep 1, 2026Updated 2 weeks ago
- Inline proxy for software package registries to provide observability and policy controls to installs.☆53Jun 5, 2026Updated 3 months ago
- A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.☆27Apr 20, 2026Updated 5 months ago
- A powerful containerized tool that automatically downloads, extracts, and scans packages from PyPI and npm for embedded secrets, API keys…☆20Jul 25, 2025Updated last year
- Notion C2 Profile for Mythic☆48Apr 30, 2026Updated 4 months ago
- Octoscan is a static vulnerability scanner for GitHub action workflows.☆272Mar 30, 2026Updated 5 months ago
- Crawl and analyze JavaScript for secrets, tokens, and API endpoints. A powerful bug bounty tool for automated JS analysis.☆28Aug 30, 2026Updated 3 weeks ago
- MCP Attack Surface Detector - Burp plugin to make manual testing of MCP servers easier in Burp Suite☆33Feb 26, 2026Updated 6 months ago
- This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) an…☆150Feb 4, 2026Updated 7 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- A simple web viewer for TruffleHog JSON output.☆21Jan 7, 2026Updated 8 months ago
- JamfHound is a python3 project designed to collect and identify attack paths in Jamf Pro tenants based on existing object permissions by …☆137Apr 23, 2026Updated 4 months ago
- MCP Snitch is a macOS application that intercepts and monitors MCP server communications, providing security analysis, access control, an…☆94Oct 14, 2025Updated 11 months ago
- Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!☆136Mar 11, 2026Updated 6 months ago
- The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2…☆65Updated this week
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆171May 8, 2026Updated 4 months ago
- Jailbreaker is a local evaluation tool for testing chatbot and agent-style systems against jailbreak, prompt-injection, and related failu…☆107Updated this week