yacwagh / FAAST
Prototype of Full Agentic Application Security Testing, FAAST = SAST + DAST + LLM agents
☆33Updated this week
Alternatives and similar repositories for FAAST:
Users that are interested in FAAST are comparing it to the libraries listed below
- This repository hosts several snippets and file related to the BsidesLV 2024 talk about Shadow and Zombie APIs by me☆18Updated 8 months ago
- A collection of Turbo Intruder scripts.☆58Updated 2 months ago
- WhereToGo - is a list of popular services that might be used in organizations. By having an account of the user - you can try to find ent…☆122Updated 2 years ago
- ☆62Updated 4 months ago
- The Arcanum Prompt Injection Taxonomy☆60Updated last week
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- ☠️ Code for the Defcon Workshop☆23Updated 8 months ago
- ☆26Updated 7 months ago
- ☆35Updated last month
- ☆60Updated this week
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆30Updated 3 months ago
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities☆27Updated last month
- A tool for quickly evaluating IAM permissions in AWS.☆57Updated last year
- A web security research tool for DOM testing☆20Updated last week
- Verizon Burp Extensions: AI Suite☆127Updated last week
- HazProne is a Cloud Pentesting Framework that emulates close to Real-World Scenarios by deploying Vulnerable-By-Demand AWS resources enab…☆39Updated 2 years ago
- Cloud subdomains identification tool☆56Updated 2 weeks ago
- Additional active scan checks for BURP☆27Updated 6 months ago
- Nuclei plugins to audit Chrome extensions☆64Updated 9 months ago
- Finds graphql queries in javascript files☆60Updated 11 months ago
- Simple PoC for demonstrating Race Conditions on Websockets☆56Updated last year
- ai-based domain name generation☆87Updated 2 months ago
- CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).☆116Updated 3 weeks ago
- A multi-cloud DNS record scanner that aims to help cybersecurity/IT analysts identify dangling CNAME records in their cloud DNS services …☆49Updated 2 years ago
- ☆30Updated last week
- Frogy 2.0 is an automated external reconnaissance and Attack Surface Management (ASM) toolkit☆73Updated 3 weeks ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆30Updated last month
- A Burp extension to help pentesters copy requests / responses for reports.☆38Updated 4 months ago
- A simple web app to get the latest EPSS data for a CVE ID☆10Updated 3 weeks ago