Submit your favorite resources for free.
Browse the newest offensive security tools, platforms, and services recently added to HackDB.
Graphw00f is a GraphQL server engine fingerprinting tool. It identifies backend technologies and security defenses by analyzing unique endpoint responses.
Garak is an LLM vulnerability scanner that probes for weaknesses like prompt injection, data leakage, hallucination, and toxicity.
Practical measures for enterprises to secure AI and LLM technology adoption, reducing security risks with pragmatic advice.
ModelScan: scans ML models for unsafe code, supporting H5, Pickle, and SavedModel formats, protecting against serialization attacks.
Assess the security of your GraphQL apps: authorization, access control, complexity limits, introspection, DDOS, and injections.
Kiterunner is a contextual content discovery tool for modern web applications and APIs, excelling in route/endpoint bruteforcing.
GraphQL Cop is a Python utility for running security tests against GraphQL APIs, ideal for CI/CD checks and vulnerability reproduction.
crAPI is a completely ridiculous API vulnerable by design, built on a microservices architecture, designed to help understand API security risks.
Altair GraphQL Client is a feature-rich IDE for debugging GraphQL queries and implementations across all platforms, simplifying development workflows.
GraphQL Voyager: Visualize any GraphQL API as an interactive graph, aiding in understanding and exploration of its schema and relationships.
APIsec University offers free API security training courses to help you find API vulnerabilities and keep your APIs secure.
Learn API testing techniques, including API recon, documentation analysis, endpoint identification, and prevention of common API vulnerabilities.