Tool · validationopt-in
Interactsh
Out-of-band interaction client for detecting blind SSRF/RCE/SQLi/XXE via callbacks.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Tagsvalidation
More tools
- keyhacks.shvalidationBash tool that checks the validity of leaked API keys and tokens across 50+ services (AWS, Azure, GCP, Slack, Stripe, GitHub, etc.) by issuing test requests. Useful for triaging secrets found during authorized assessments.
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.
- AI Vuln Scannerdast/web-app-scannerA security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.
- Aktoapi-securityOpen-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.
- AmassreconDeep passive subdomain enumeration across many public sources.
- ArjundiscoveryDiscovers hidden HTTP parameters using a bundled (SecLists-upsizable) wordlist.