8000 GitHub - OMIXEC/Top-API-Hacking-Tools: A curated list of the top API hacking tools
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

OMIXEC/Top-API-Hacking-Tools

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

2 Commits
Β 
Β 

Repository files navigation

Ultimate API Hacking Tools Directory [2025]

A curated collection of 60+ open-source tools for API security testing, penetration testing, and vulnerability research. Organized by API type and functionality.


🌐 REST API Security Tools

Tool Description GitHub
Akto API discovery & business logic testing akto-api-security/akto
APIClarity OpenAPI spec reconstruction openclarity/apiclarity
APICheck DevSecOps toolset for REST APIs BBVA/apicheck
Astra Automated REST API security testing flipkart-incubator/astra
CATS REST API fuzzer for OpenAPI Endava/cats
Cherrybomb API spec validator blst-security/cherrybomb
ffuf Fast web fuzzer (Go) ffuf/ffuf
kiterunner Contextual content discovery assetnote/kiterunner
RESTler Stateful REST API fuzzer microsoft/restler-fuzzer
mitmproxy2swagger API reverse-engineering alufers/mitmproxy2swagger

πŸ•ΈοΈ GraphQL Security Tools

Tool Description GitHub
InQL Burp Suite GraphQL extension doyensec/inql
GraphQLmap GraphQL pentesting engine swisskyrepo/GraphQLmap
graphql-cop GraphQL security auditor dolevf/graphql-cop
clairvoyance Schema extraction tool nikitastupin/clairvoyance
graphw00f GraphQL fingerprinting dolevf/graphw00f

🧩 SOAP API Tools

Tool Description GitHub
Wsdler WSDL parser for Burp portswigger/wsdler
SoapUI API functional testing SmartBear/soapui

πŸ› οΈ General API Security

Tool Description GitHub
ZAP OWASP API scanner zaproxy/zaproxy
Metlo API security platform metlo-labs/metlo
apisec Multi-API security scanner vkvbit/apisec
Step CI API QA framework stepci/stepci

πŸ” Reconnaissance Tools

Tool Description GitHub
gau URL discovery tool lc/gau
gitGraber GitHub secrets monitor hisxo/gitGraber
Shhgit Sensitive file finder eth0izzle/shhgit
Masscan High-speed port scanner robertdavidgraham/masscan

πŸ—οΈ Frameworks & Collections

Tool Description GitHub
reNgine Automated recon framework yogeshojha/rengine
HackerOne Tools HackerOne API utilities Hacker0x01/hackerone-tools

πŸ§ͺ Fuzzing & Negative Testing

Tool Description GitHub
APIFuzzer OpenAPI/Swagger fuzzer localstack/apifuzzer
fuzz-lightyear Stateful Swagger fuzzer Yelp/fuzz-lightyear
fuzzapi REST API fuzzing engine fuzzapi/fuzzapi
TnT-Fuzzer Swagger schema fuzzer Teebytes/TnT-Fuzzer
WuppieFuzz Coverage-guided API fuzzer PortSwigger/wuppiefuzz

πŸ•΅οΈ API Recon & Analysis

Tool Description GitHub
wadl-dumper WADL endpoint extractor pentestmonkey/wadl-dumper
noir Attack surface detector noir-crs/noir
Commit-stream GitHub commit analyzer commit-stream/commit-stream
unfurl URL component analyzer tomnomnom/unfurl

πŸ›‘οΈ Defensive & Audit Tools

Tool Description GitHub
graphql-armor GraphQL security layer escape-technologies/graphql-armor
Gosec Go code security scanner securego/gosec
dredd API contract testing apiaryio/dredd

🧰 Specialized Toolkits

Tool Description GitHub
BatchQL GraphQL batch attack tool assetnote/batchql
graphql-path-enum Schema path analyzer dolevf/graphql-path-enum
graphql-threat-matrix Attack framework nettitude/graphql-threat-matrix
goctopus GraphQL discovery toolkit bregydoc/goctopus

πŸ”— Integration Tools

Tool Description GitHub
Swagger-EZ OpenAPI pentesting suite swagger-ez/swagger-ez
OFFAT OWASP API assessment tool offat/offat
REST-Attacker REST security framework saschahlusiak/REST-Attacker

πŸ“œ Documentation Tools

Tool Description GitHub
Optic OpenAPI spec maintainer opticdev/optic
graphql-playground GraphQL IDE graphql/graphql-playground

πŸ“š Resources


#Disclaimer Legal Notice: These tools are for authorized security testing only. Always obtain proper permissions before testing any system.

Author: OMIXEC

About

A curated list of the top API hacking tools

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published
0