cherrybomb

API auditor

A tool that audits and tests API specifications to prevent security errors and ensures APIs function as intended.

Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

GitHub

1k stars
12 watching
83 forks
Language: Rust
last commit: almost 2 years ago
Linked from 2 awesome lists

apiapi-securitybest-practicesblstbusiness-logicclicybercybersecurityfirecrackerhttpopen-sourceopenapiopenapi3securitysecurity-toolsweb-sec-scannerweb-securitywebsecurity

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
peachtech/peachapisec-burpA tool for integrating automated security testing with web API analysis in Burp Suite2
azure/counterfitAn automation tool that assesses the security of machine learning systems by bringing together various adversarial frameworks under one platform.818
gitguardian/apisecuritybestpracticesResources to help developers keep sensitive information secret and mitigate potential security breaches1,923
gosecure/csp-auditorAnalyzes and configures website security policies to prevent malicious scripts from running on user devices.138
zalando/zallyA tool that helps ensure APIs are well-designed and follow best practices by analyzing their specifications against established guidelines.914
trapexit/scorchA tool to catalog files and their hashes to help in discovering file corruption, missing files, duplicates, etc.199
chrisbjr/api-guardA package for authenticating RESTful APIs with API keys in Laravel691
riverloopsec/killerbeeA toolkit for testing and auditing ZigBee and IEEE 802.15.4 networks767
zimmski/go-mutestingA tool to detect untested parts of source code by introducing small changes and testing the resulting behavior.650
cisagov/csetTools to evaluate and improve cybersecurity posture in industrial control systems and information technology architecture1,473
d35ha/callobfuscatorTools for modifying Windows API imports to evade analysis and detection by static/dynamic analysis tools.984
debasishm89/burpyA tool that analyzes web application security by parsing Burp Suite logs and generating reports.120
portswigger/html5-auditorAn HTML validation and security testing tool for identifying vulnerabilities in web applications4
bearer/bearerA tool for discovering and prioritizing security risks in software code2,112
cgboal/sonarsearchAn API for querying and searching the Project Sonar dataset using Go.642