Burp Suite extension for authorization testing in Java serialized communication: decode, inspect, and edit serialized objects live
-
Updated
Aug 26, 2026 - Python
Burp Suite extension for authorization testing in Java serialized communication: decode, inspect, and edit serialized objects live
Authorization testing for REST APIs and MCP servers. Declare who may do what as a matrix, and overstep turns it into positive and negative tests that catch BOLA, BFLA, BOPLA and privilege escalation — with drift baselines, confidence grading and CWE/OWASP-tagged SARIF for CI.
ReqEye is a CLI assistant for HTTP request analysis, designed to help security researchers, bug bounty hunters, and pentesters identify high‑value entry points worth manual testing. It does not scan targets, send traffic, or claim vulnerabilities. ReqEye focuses on where to look, not on making assumptions.
MCP server for autonomous API logic penetration testing. AI-driven detection of OWASP API Top 10 vulnerabilities (BOLA/IDOR) via multi-session authorization comparison. Supports Bearer, Basic, API Key, Cookie auth. Generates Markdown security audit reports with evidence.
3-stage authorized security pipeline: CDP mapper, multi-actor permission matrix, and automated PoC generation
CI-native differential authorization regression testing for Python—replay exact permission cases, enforce invariants, and catch DENY→ALLOW changes.
To associate your repository with the authorization-testing topic, visit your repo's landing page and select "manage topics."