Everything related to attacking and securing modern APIs including REST, GraphQL, gRPC, and more. Covers broken authentication, IDOR, mass assignment, BOLA, rate limiting, and JWT flaws. Includes real-world exploits, recon techniques, gateway bypasses, and best-in-class tooling for testing and exploitation.

Aikido is a security platform for code and cloud, designed to automatically find and fix vulnerabilities in one central system.

Arjun is an HTTP parameter discovery suite to find valid web parameters and uncover hidden endpoints.

AI-native SAST tool for code security, detecting vulnerabilities, secrets, IaC issues, and AI model security with actionable AI fixes.