Tools
Tool · api-securityactive

BurpAPISecuritySuite

A Burp Suite extension for API security testing that auto-captures and normalizes API traffic, groups endpoints, and generates fuzzing campaigns covering OWASP API Top 10 issues (BOLA/IDOR, SQLi, XSS, NoSQLi, XXE, JWT abuse, GraphQL abuse, race conditions). It exports to Burp Intruder/Turbo Intruder, Nuclei, and external tools (SQLMap, Dalfox, HTTPX, Katana, FFUF), and is actively maintained (v1.4.15, MIT).

Use responsibly

Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.

More tools