All resources
Topic

api-security

5 resources across 1 kinds

Tools

  1. Aktohostedopt-in

    Open-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.

    Open ↗
  2. EvoMasteractiveopt-in

    State-of-the-art REST API fuzzer with a dedicated authorization SECURITY phase that flags access-control faults from two authenticated users.

    Open ↗
  3. GraphQLeractive

    Dependency-aware GraphQL security tester that builds the query/mutation graph and runs two-profile cross-user IDOR/BOLA checks.

    Open ↗
  4. Hadrianactive

    Praetorian's headless OWASP-API authorization scanner covering BOLA, BFLA, OTP-brute/no-rate-limit ATO and mass-assignment with setup-attack-verify proof.

    Open ↗
  5. A Burp Suite extension for API security testing that auto-captures and normalizes API traffic, groups endpoints, and generates fuzzing campaigns covering OWASP API Top 10 issues (BOLA/IDOR, SQLi, XSS, NoSQLi, XXE, JWT abuse, GraphQL abuse, race conditions). It exports to Burp Intruder/Turbo Intruder, Nuclei, and external tools (SQLMap, Dalfox, HTTPX, Katana, FFUF), and is actively maintained (v1.4.15, MIT).

    Open ↗