
atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.

Small and highly portable detection tests based on MITRE's ATT&CK.

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

eBPF-powered Kubernetes monitoring and performance testing platform that automatically generates service maps, tracks real-time metrics, and runs…

Project Wycheproof tests crypto libraries against known attacks.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Penetration tests guide based on OWASP including test cases, resources and examples.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Tips and Tutorials for Bug Bounty and also Penetration Tests.

Automating situational awareness for cloud penetration tests.

Exploits Windows IPv6 default configuration to spoof DNS via DHCPv6, redirecting victim traffic for credential relaying and man-in-the-middle attacks…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Crowbar is brute forcing tool that can be used during penetration tests. It is developed to support protocols that are not currently supported by…

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Performing security tests inside your CI

Tests your WAF with +160 payloads

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…