Automatic authorization enforcement detection extension for Burp Suite written in Jython, developed by Barak Tawily, to ease application security people's work and allow them to perform automatic authorization tests.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
OpenRASP directly integrates its protection engine into the application server by instrumentation, providing context-aware protection and detailed stack trace logging.
An API security platform that provides automated security testing, runtime protection, and lifecycle management for APIs through integrated tools and controls.
Cutting-edge technology for developing security applications within the Linux kernel.
Insider is a source code analysis tool focusing on OWASP Top 10 vulnerabilities with easy integration into DevOps pipelines.
A comprehensive cheatsheet for XSS filter evasion techniques.
Goof is a vulnerable Node.js demo application that includes a series of vulnerabilities and exploits
An API security platform that combines discovery, compliance monitoring, and protection capabilities to defend against API attacks, automated threats, and data exposure.
AWS Web Application Firewall (WAF) for protecting web applications from common exploits.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.