You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and automated reconnaissance. Supports REST/GraphQL/SOAP APIs with Nuclei, Turbo Intruder, and external tool integration. OWASP API Top 10 coverage.
🚀 Join us for 30days of daily API security tests. #30days30tests We've spent last 120days building amazing API security tests for the community. Next 30 days we will post test tutorials here.
Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traffic by listener port (PwnFox-style) — built for Android/iOS multi-account IDOR/BOLA testing, with Magic Cookie, Match & Replace, and .http export for Claude Code / AI.
AI writes. SPARDA proves. A deterministic, offline gate that catches when an AI edit removes a guard, exposes a route, or breaks an invariant — no API key, right in the agent edit loop.
🛡️ Multi-tenant isolation auditor — proves whether tenant A can reach tenant B's data. Seeds two tenants, attacks one as the other, and reports confirmed BOLA/IDOR leaks with canary-backed evidence. CI merge gate, near-zero false positives. One command: docker compose up -d
A lightweight, high-performance browser extension (Manifest V3) designed for penetration testers and ethical hackers. Features passive HTTP traffic inspection, automated IDOR/BOLA scoring, noise filtering, and AI-driven vulnerability analysis with PDF report generation. Built for ethical security research.
AuthForge analyzes Burp traffic to learn actor to object relationships and validate BOLA/IDOR vulnerabilities using independent control objects. Dry run by default, with mutations enabled only through explicit flags.
Local-first security recon for AI coding agents: map attack surfaces, stage tailored probes, and produce a fact-grounded brief. Part of the Guard family with DocGuard and TestGuard.
Authorization testing for REST APIs and MCP servers. Declare who may do what as a matrix, and overstep turns it into positive and negative tests that catch BOLA, BFLA, BOPLA and privilege escalation — with drift baselines, confidence grading and CWE/OWASP-tagged SARIF for CI.