13 repository-uri
Tools for testing running applications for security flaws.
Explore 13 awesome GitHub repositories matching part of an awesome list · Dynamic Analysis. Refine with filters or upvote what's useful.
Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ
Template-based security scanning for web applications.
OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.
Open-source web application vulnerability scanner with CI/CD support.
OSS-Fuzz is a distributed, containerized platform for continuous fuzzing and memory safety analysis. It functions as a bug hunting infrastructure that identifies security vulnerabilities and stability bugs through automated, coverage-guided fuzz testing across a scalable cluster of containers. The system provides a continuous security testing pipeline that manages the entire lifecycle of vulnerability discovery, from bootstrapping project templates and compiling targets to executing long-running batch tests. It specifically focuses on memory safety, utilizing sanitizers to detect buffer overf
Continuous fuzzing for open source software.
Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a reconnaissance engine designed to identify insecure server options, outdated software, and common vulnerabilities by analyzing HTTP responses. The project differentiates itself through capabilities for intrusion detection evasion and web server fingerprinting. It uses request-level encoding and timing spacers to bypass security filters and employs signature-based identification to determine specific server software versions and misconfigurations. The scanner covers broad capability are
Web server security scanner.
RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.
Stateful fuzzer for testing RESTful API endpoints.
Web vulnerability scanner written in Python3
Lightweight web application security scanner.
A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing.
Automated scanning for SSL and TLS configuration issues.
Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure
API security testing with automated test suites.
a ruggedization framework that embodies the principle "be mean to your code"
Behavior-driven security testing framework using common tools.
Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.
Automated security scanning for APIs based on specifications.
Discover internet-wide misconfigurations while drinking coffee
Tool for discovering internet-wide misconfigurations.
CLI component of OWASP PurpleTeam
CLI-based dynamic security testing tool.
Cake Fuzzer is a project that is meant to help automatically and continuously discover vulnerabilities in web applications created based on specific frameworks with very limited false positives.
Automated vulnerability discovery for CakePHP applications.