awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to imperva/automatic-api-attack-tool

Open-source alternatives to Automatic Api Attack Tool

30 open-source projects similar to imperva/automatic-api-attack-tool, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Automatic Api Attack Tool alternative.

  • microsoft/restler-fuzzermicrosoft avatar

    microsoft/restler-fuzzer

    2,915View on GitHub↗

    RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.

    Python
    View on GitHub↗2,915
  • blst-security/cherrybombblst-security avatar

    blst-security/cherrybomb

    1,231View on GitHub↗

    Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

    Rust
    View on GitHub↗1,231
  • flipkart-incubator/astraflipkart-incubator avatar

    flipkart-incubator/Astra

    2,639View on GitHub↗

    Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles. The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports. The system supports the import of collection files to map endpoints

    Pythonci-cdowasppenetration-testing
    View on GitHub↗2,639
  • akto-api-security/aktoakto-api-security avatar

    akto-api-security/akto

    1,486View on GitHub↗

    Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure

    Java
    View on GitHub↗1,486

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • andresriancho/w3afandresriancho avatar

    andresriancho/w3af

    4,850View on GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    View on GitHub↗4,850
  • manisso/fsocietyManisso avatar

    Manisso/fsociety

    12,136View on GitHub↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    Pythonbrute-force-attacksdesktopexploitation
    View on GitHub↗12,136
  • cujanovic/ssrf-testingcujanovic avatar

    cujanovic/SSRF-Testing

    2,501View on GitHub↗

    SSRF (Server Side Request Forgery) testing resources

    Pythonpentestpentest-toolpentesting
    View on GitHub↗2,501
  • ambionics/phpggcambionics avatar

    ambionics/phpggc

    3,832View on GitHub↗

    phpggc is a security assessment utility and command-line tool designed for the automated generation, obfuscation, and wrapping of serialized object chains. It functions as a gadget chain framework used to identify and verify remote code execution vectors by testing for PHP object injection vulnerabilities. The project provides a modular system for constructing complex serialized object sequences and includes a dedicated payload obfuscator to transform byte streams for bypassing web application firewalls and security filters. It also features a generator for wrapping serialized data into archi

    PHP
    View on GitHub↗3,832
  • akto-api-security/community-editionA

    akto-api-security/community-edition

    0View on GitHub↗
    View on GitHub↗0
  • flozz/p0wny-shellflozz avatar

    flozz/p0wny-shell

    2,825View on GitHub↗

    p0wny@shell:~# is a very basic, single-file, PHP shell. It can be used to quickly execute commands on a server when pentesting a PHP application. Use it with caution: this script represents a security risk for the server.

    PHP
    View on GitHub↗2,825
  • centralmind/gatewaycentralmind avatar

    centralmind/gateway

    530View on GitHub↗

    Universal MCP-Server for your Databases optimized for LLMs and AI-Agents.

    Go
    View on GitHub↗530
  • cerberauth/vulnapiC

    cerberauth/vulnapi

    0View on GitHub↗
    View on GitHub↗0
  • google/oss-fuzzgoogle avatar

    google/oss-fuzz

    12,353View on GitHub↗

    OSS-Fuzz is a distributed, containerized platform for continuous fuzzing and memory safety analysis. It functions as a bug hunting infrastructure that identifies security vulnerabilities and stability bugs through automated, coverage-guided fuzz testing across a scalable cluster of containers. The system provides a continuous security testing pipeline that manages the entire lifecycle of vulnerability discovery, from bootstrapping project templates and compiling targets to executing long-running batch tests. It specifically focuses on memory safety, utilizing sanitizers to detect buffer overf

    Shell
    View on GitHub↗12,353
  • dwisiswant0/wadl-dumperdwisiswant0 avatar

    dwisiswant0/wadl-dumper

    98View on GitHub↗

    Dump all available paths and/or endpoints on WADL file.

    Go
    View on GitHub↗98
  • assetnote/kiterunnerassetnote avatar

    assetnote/kiterunner

    3,204View on GitHub↗

    Contextual Content Discovery Tool

    Go
    View on GitHub↗3,204
  • alufers/mitmproxy2swaggeralufers avatar

    alufers/mitmproxy2swagger

    9,530View on GitHub↗

    mitmproxy2swagger is a tool that transforms captured mitmproxy network traffic into structured OpenAPI schemas for reverse-engineering REST APIs. It functions as an OpenAPI schema converter and network traffic documentation utility, extracting API endpoints and data structures from captured network packets to create formal technical references. The tool enables the reconstruction of undocumented APIs by converting intercepted HTTP request and response patterns into specifications. It supports merging multiple traffic capture files into a single schema to incrementally expand an API map and ut

    HTMLmitmproxyopenapireverse-engineering
    View on GitHub↗9,530
  • espreto/wpsploitespreto avatar

    espreto/wpsploit

    233View on GitHub↗

    WPSploit - Exploiting Wordpress With Metasploit

    Ruby
    View on GitHub↗233
  • epinna/tplmapepinna avatar

    epinna/tplmap

    4,169View on GitHub↗

    tplmap is a security tool designed for the detection and exploitation of server-side template injection vulnerabilities. It functions as an automated scanner to identify vulnerable template engine contexts and provides a framework for achieving remote code execution. The tool focuses on translating high-level requests into engine-specific syntax to execute operating system commands and bypass application sandboxes. It further enables remote file system access, allowing users to read, write, and transfer files between a local machine and a target server. Additional capabilities include the ab

    Python
    View on GitHub↗4,169
  • evyatarmeged/raccoonevyatarmeged avatar

    evyatarmeged/Raccoon

    3,571View on GitHub↗

    A high performance offensive security tool for reconnaissance and vulnerability scanning

    Python
    View on GitHub↗3,571
  • ffuf/ffufffuf avatar

    ffuf/ffuf

    15,618View on GitHub↗

    This tool is a command-line utility designed for automated web resource discovery, fuzzing, and application structure mapping. It functions as a security-focused scanner that identifies hidden files, directories, parameters, and virtual hosts by injecting payloads into HTTP requests. By systematically testing how servers handle various inputs, it assists in mapping the architecture of web applications and uncovering potential security vulnerabilities. The tool distinguishes itself through a highly concurrent engine that manages asynchronous request execution and recursive job orchestration. I

    Gofuzzerinfosecpentesting
    View on GitHub↗15,618
  • apiclarity/apiclarityapiclarity avatar

    apiclarity/apiclarity

    572View on GitHub↗

    An API security tool to capture and analyze API traffic, test API endpoints, reconstruct Open API specification, and identify API security risks.

    Go
    View on GitHub↗572
  • enjoiz/xxeinjectorenjoiz avatar

    enjoiz/XXEinjector

    1,754View on GitHub↗

    Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.

    Ruby
    View on GitHub↗1,754
  • frohoff/ysoserialfrohoff avatar

    frohoff/ysoserial

    8,750View on GitHub↗

    ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java deserialization. It functions as a framework for creating malicious serialized objects that can trigger remote code execution on Java virtual machines. The project provides a library of known gadget chains, which are sequences of vulnerable class calls that achieve arbitrary command execution during the deserialization process. It automates the generation of these payloads by leveraging common third-party libraries. The tool covers capabilities for security penetration testing, Java app

    Javadeserializationexploitgadget
    View on GitHub↗8,750
  • fuzzapi/fuzzapiFuzzapi avatar

    Fuzzapi/fuzzapi

    665View on GitHub↗

    Fuzzapi is a tool used for REST API pentesting and uses API_Fuzzer gem

    Ruby
    View on GitHub↗665
  • fuzzdb-project/fuzzdbfuzzdb-project avatar

    fuzzdb-project/fuzzdb

    8,819View on GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    PHP
    View on GitHub↗8,819
  • gauntlt/gauntltgauntlt avatar

    gauntlt/gauntlt

    996View on GitHub↗

    a ruggedization framework that embodies the principle "be mean to your code"

    Ruby
    View on GitHub↗996
  • endava/catsEndava avatar

    Endava/cats

    1,359View on GitHub↗

    CATS is a REST API Fuzzer and negative testing tool for OpenAPI endpoints. CATS automatically generates, runs and reports tests with minimum configuration and no coding effort. Tests are self-healing and do not require maintenance.

    Java
    View on GitHub↗1,359
  • illuminopi/rcevil.netI

    Illuminopi/RCEvil.NET

    0View on GitHub↗
    View on GitHub↗0
  • internetwache/gittoolsinternetwache avatar

    internetwache/GitTools

    4,151View on GitHub↗

    GitTools is a collection of security utilities designed to identify, scan, and exploit exposed version control directories on web servers. The project provides tools to locate publicly accessible Git directories and extract their contents to identify information leaks. The suite includes capabilities for downloading files and folder structures from remote repositories even when directory listing is disabled. It also features a recovery system that iterates through commit objects to restore content from incomplete or corrupted version control data.

    Shell
    View on GitHub↗4,151
  • api-security/apikitAPI-Security avatar

    API-Security/APIKit

    2,270View on GitHub↗

    APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

    Java
    View on GitHub↗2,270