APISCAN is a Swagger-driven API security tool for security specialists and auditors, focused on OWASP API Top 10 coverage and evidence-based reporting.
-
Updated
Jul 8, 2026 - Python
APISCAN is a Swagger-driven API security tool for security specialists and auditors, focused on OWASP API Top 10 coverage and evidence-based reporting.
Practical walkthrough of OWASP API Top 10 vulnerabilities with real exploitation steps and effective security fixes.
A novel LLM-driven Fuzzer for unsafe API consumption testing
ZeroShield API Security Platform is a full-lifecycle API security solution for discovering, testing, and protecting REST, SOAP, and GraphQL APIs with agentless scans, real-time runtime protection, AI-powered remediation, and compliance-grade OWASP/CWE/CVSS mapping.
OWASP API Top 10 assessment — BOLA, broken auth, JWT algorithm confusion, mass assignment exploitation
API security lab demonstrating vulnerability scanning using Qualys, Aikido, and Wallarm with real-world findings and remediation strategies
Secured a vulnerable Spring Boot REST API by fixing OWASP API Security Top 10 (2023) issues, implementing JWT authentication, role-based access control, input validation, DTOs, and rate limiting.
API security testing engine for detecting OWASP API vulnerabilities and business logic flaws.
Notes, labs, cheatsheets, and certificate for the API Penetration Testing (ApiSec University) course. Focuses on OWASP API Top 10, attack techniques, and secure API design.
Add a description, image, and links to the owasp-api-top10 topic page so that developers can more easily learn about it.
To associate your repository with the owasp-api-top10 topic, visit your repo's landing page and select "manage topics."