LogoHackDB
RecentCategoryTagPricingSubmit
Sign In
LogoHackDB
Sign In
LogoHackDB

The Ultimate Directory for Offensive Security

Resources
  • Recent
  • Category
  • Tag
  • Listing
    • Pricing
    • FAQ
    • Submit
    Pages
    • Home
    • Support
    • Sitemap
    • llms.txt
    Company
    • About Us
    • Privacy Policy
    • Terms of Service
    Copyright © 2026 All Rights Reserved.

    Category

    API Security

    API security covers attacking and securing modern REST, GraphQL, and gRPC endpoints via IDOR, BOLA, JWT flaws, and rate-limiting bypass techniques.

    Back to categories
    • Previous
    • 1
    • 2
    • 3
    • Next
    image of GraphQL Voyager
    API Security
    Visit Website

    GraphQL Voyager

    Details

    GraphQL Voyager: Visualize any GraphQL API as an interactive graph, aiding in understanding and exploration of its schema and relationships.

    API
    image of GraphQLmap
    API SecurityApplication Security
    Visit Website

    GraphQLmap

    Details

    GraphQLmap is a scripting engine for GraphQL endpoint pentesting, automating queries and fuzzing for vulnerabilities.

    API
    image of InQL
    API Security
    Visit Website

    InQL

    Details

    InQL is a Burp Suite extension for advanced GraphQL testing, offering vulnerability detection and customizable scans.

    API
    image of JWT Debugger
    Application SecurityAPI Security
    Visit Website

    JWT Debugger

    Details

    JWT Debugger is a web application to create, encode, decode, and debug JWT (JSON Web Tokens). It helps developers inspect claims and test token integrity.

    WebAPIStatic Analysis
    image of Kiterunner
    API SecurityReconnaissance
    Visit Website

    Kiterunner

    Details

    Kiterunner is a contextual content discovery tool for modern web applications and APIs, excelling in route/endpoint bruteforcing.

    APIBruteforceWeb
    image of Moxy
    Application SecurityAPI SecurityAI Security
    Visit Website

    Moxy

    Details

    Moxy is an open-source DAST tool with agentic AI for modern web application security testing and automated pentesting workflows.

    AIAPIWeb
    image of Porch Pirate
    API SecurityReconnaissance
    Visit Website

    Porch Pirate

    Details

    A Postman recon/OSINT framework for automated API endpoint discovery and secret exploitation in workspaces, collections, requests, users, and teams.

    OSINTAPIBug Bounty
    image of Postman
    Application SecurityAPI Security
    Visit Website

    Postman

    Details

    Postman: The leading API platform for building and using APIs. Streamline collaboration and simplify the API lifecycle.

    APIWebMobile
    image of Prism
    API Security
    Visit Website

    Prism

    Details

    Prism is an open-source HTTP mock and proxy server that accelerates API development with realistic mock servers powered by OpenAPI documents.

    API
    image of RESTler
    API SecurityCloud Security
    Visit Website

    RESTler

    Details

    RESTler is a stateful REST API fuzzing tool for automatically testing cloud services and finding security and reliability bugs.

    APIBug Bounty
    image of RunSybil
    AI SecurityVulnerability IntelligenceRed Team OperationsApplication SecurityAPI Security
    Visit Website

    RunSybil

    Details

    AI-driven pentesting platform automating hacker intuition to find vulnerabilities before exploits, reducing discovery costs.

    AIVulnerability IntelligenceReportAPIWeb+4
    image of Salt Security
    API SecurityAI SecurityCloud SecurityApplication Security
    Visit Website

    Salt Security

    Details

    AI-infused API Security solution for the entire API lifecycle, from discovery and posture management to threat protection, including AI Agents.

    APIAICloudVulnerability IntelligenceReport+2