swisskyrepo / GraphQLmapLinks
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
☆1,586Updated last year
Alternatives and similar repositories for GraphQLmap
Users that are interested in GraphQLmap are comparing it to the libraries listed below
Sorting:
- InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable…☆1,700Updated last week
- Obtain GraphQL API schema even if the introspection is disabled☆1,319Updated last week
- PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.☆1,249Updated last year
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3☆2,038Updated last year
- Making Favicon.ico based Recon Great again !☆1,250Updated 2 years ago
- ☆1,397Updated 3 months ago
- The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.☆1,258Updated 10 months ago
- A wordlist of API names for web application assessments☆857Updated 5 months ago
- Subdomain takeover vulnerability checker☆1,445Updated last year
- A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..e…☆1,001Updated last year
- ☆1,062Updated 2 months ago
- Automated & Manual Wordlists provided by Assetnote☆1,579Updated 2 weeks ago
- GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep☆1,382Updated last year
- A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.☆916Updated 3 weeks ago
- An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects☆968Updated 4 years ago
- XSS payloads designed to turn alert(1) into P1☆1,378Updated 2 years ago
- MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering…☆1,534Updated last week
- Fetch many paths for many hosts - without killing the hosts