API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs
☆110Jul 21, 2026Updated this week
Alternatives and similar repositories for vespasian
Users that are interested in vespasian are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven te…☆68Updated this week
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆86Jul 10, 2026Updated last week
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆167Updated this week
- Simple LLM service identification - translate IP:Port to Ollama, vLLM, LiteLLM, or 60+ other AI services in seconds☆78Updated this week
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated 2 weeks ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian☆316Updated this week
- GitHub Action to alert on security patches before the CVE drops.☆215Jul 5, 2026Updated 2 weeks ago
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆70Nov 27, 2025Updated 7 months ago
- Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra al…☆288Updated this week
- AI-Powered Web Attack Surface Enumeration☆44Feb 5, 2026Updated 5 months ago
- Open-source cloud security reconnaissance framework☆62Updated this week
- High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential v…☆641Updated this week
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆367Jun 27, 2026Updated 3 weeks ago
- A golang-written credential harvesting framework leveraging eBPF for kernel-level monitoring with anti-detection capabilities.☆48Apr 13, 2026Updated 3 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A POC tool for exploring dev-tunnels☆66May 5, 2026Updated 2 months ago
- LLM security testing framework for detecting prompt injection, jailbreaks, and adversarial attacks — 190+ probes, 28 providers, single Go…☆260Updated this week
- GitHub Workflows Insights☆47Jun 27, 2026Updated 3 weeks ago
- Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.☆56Jul 15, 2026Updated last week
- A simple web viewer for TruffleHog JSON output.☆21Jan 7, 2026Updated 6 months ago
- ☆17Apr 16, 2026Updated 3 months ago
- ☆18Sep 9, 2025Updated 10 months ago
- A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.☆25Apr 20, 2026Updated 3 months ago
- Did you contain the compromised identity? notyet☆42Updated this week
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Pentester-focused Docker registry tool to enumerate and pull images☆41Oct 19, 2025Updated 9 months ago
- Audit content (pdfs, media files, images) sensitivity on urls☆45Jun 2, 2026Updated last month
- MCP Attack Surface Detector - Burp plugin to make manual testing of MCP servers easier in Burp Suite☆30Feb 26, 2026Updated 4 months ago
- Notion C2 Profile for Mythic☆47Apr 30, 2026Updated 2 months ago
- Check your AWS CLI commands for security risks before you run them.☆33Apr 1, 2026Updated 3 months ago
- Tokenex is a Go library that securely exchanges identity tokens for temporary cloud credentials, with built-in support for AWS, GCP, Azur…☆84Jul 13, 2026Updated last week
- JamfHound is a python3 project designed to collect and identify attack paths in Jamf Pro tenants based on existing object permissions by …☆134Apr 23, 2026Updated 2 months ago
- The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2…☆52Jun 6, 2026Updated last month
- This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) an…☆150Feb 4, 2026Updated 5 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps…☆37Jun 19, 2026Updated last month
- Inline proxy for software package registries to provide observability and policy controls to installs.☆50Jun 5, 2026Updated last month
- Universal Security Visualization library☆17May 31, 2026Updated last month
- A powerful containerized tool that automatically downloads, extracts, and scans packages from PyPI and npm for embedded secrets, API keys…☆20Jul 25, 2025Updated 11 months ago
- MCP security testing framework for evaluating Model Context Protocol server vulnerabilities☆34Feb 17, 2026Updated 5 months ago
- Crawl and analyze JavaScript for secrets, tokens, and API endpoints. A powerful bug bounty tool for automated JS analysis.☆21Apr 3, 2026Updated 3 months ago
- GitHub Actions Cache Native Malware - for Educational and Research Purposes only.☆167May 8, 2026Updated 2 months ago