StackHawk is a Dynamic Application Security Testing (DAST) platform designed for API and web application security testing. The tool integrates into CI/CD pipelines to perform automated security testing during the development process. It provides capabilities for: - API security testing across REST, GraphQL, gRPC, and SOAP APIs - Vulnerability scanning and detection - Local development testing - Integration with development tools like GitHub, JIRA, and Azure DevOps - Security issue triaging and prioritization - API discovery and attack surface mapping The platform enables development teams to identify and fix security vulnerabilities early in the software development lifecycle, with features for continuous testing and monitoring of applications in pre-production environments.
FEATURES
SIMILAR TOOLS
Python-based web server framework for setting up fake web servers and services with precise data responses.
OpenRASP directly integrates its protection engine into the application server by instrumentation, providing context-aware protection and detailed stack trace logging.
The Contrast Runtime Security Platform is a suite of application security tools that integrates security into the software development lifecycle and production environments, including IAST, SAST, RASP, and SCA capabilities.
A PHP port of Rack::Honeypot, a spam trap that detects and blocks spambots
A privacy-focused CAPTCHA alternative that protects websites from bot attacks using proof-of-work challenges and AI-based detection while maintaining GDPR compliance.
SafeLine WAF is an open-source web application firewall that protects web services by filtering malicious HTTP traffic through intelligent semantic analysis and machine learning-based detection.
Dynamic application security testing tool for identifying and fixing web application vulnerabilities.
A comprehensive cheatsheet for XSS filter evasion techniques.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.