How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.
The main features of microsoft/restler-fuzzer are: Adversary Simulation, Testing Frameworks, Dynamic Analysis, REST API Security Tools, Web Exploitation.
Open-source alternatives to microsoft/restler-fuzzer include: imperva/automatic-api-attack-tool — Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are… flipkart-incubator/astra — Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API… akto-api-security/akto — Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+… cobbr/covenant — Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… its-a-feature/apfell — Apfell is a red teaming framework and command and control server designed for collaborative adversary simulation. It…
Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.
Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles. The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports. The system supports the import of collection files to map endpoints
Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure
Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It serves as a collaborative platform for coordinating security assessments, managing remote implants, and executing tasks on compromised systems through a centralized server. The project is distinguished by its dynamic payload generator, which compiles and obfuscates executable binaries and scripts on the fly to bypass detection. It further separates itself through a collaborative environment that allows multiple authenticated operators to share a synchronized state, track operat