RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.
Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.
Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure
Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles. The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports. The system supports the import of collection files to map endpoints
Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.
Las características principales de imperva/automatic-api-attack-tool son: API Scanners, Dynamic Analysis, REST API Security Tools, Web Exploitation.
Las alternativas de código abierto para imperva/automatic-api-attack-tool incluyen: microsoft/restler-fuzzer — RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs… flipkart-incubator/astra — Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API… akto-api-security/akto — Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+… blst-security/cherrybomb — Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API… manisso/fsociety — fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits.… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities…