Practical, no-nonsense security tools born out of real engagements — every tool here is free, open-source, and actively maintained.
Python
Active
Josh API Analyzer is an API-focused security testing platform designed to help penetration testers, security researchers and VAPT teams assess APIs faster and more efficiently.
Capture traffic, analyze vulnerabilities, manually test requests, fuzz endpoints, manage authentication tokens and generate professional reports — all from one tool.
Built specifically around API security testing, with 25 selectable vulnerability detectors covering the OWASP API Security Top 10 (2023) along with classic and extended API security issues.
Capture API requests directly from a browser session, Python applications and test scripts, or import an existing HAR file. Start testing from real application traffic instead of building every request manually.
Analyze individual requests or complete captured sessions for vulnerabilities such as BOLA/IDOR, broken authentication, BFLA, SQL Injection, XSS, SSRF, JWT vulnerabilities, business logic issues, race conditions and more.
Don't blindly trust automated findings. Send requests to the built-in Repeater, modify parameters, headers or request bodies, replay them and manually verify the behaviour of the target API.
Test parameters automatically using Sniper, Battering Ram, Pitchfork and Cluster Bomb attack modes. Use built-in payloads or provide your own payload lists to explore unexpected API behaviour.
Extract authentication tokens from captured traffic and reuse them during Replay, Repeater and Intruder testing. The built-in Token Decoder also helps inspect JWT headers, claims and algorithm information.
Modern APIs rarely work as a single request. Josh API Analyzer supports workflow chaining, allowing the output of one request — such as a login token — to automatically become the input of another request.
Detector results use confidence scoring and false-positive filtering before findings are surfaced, helping VAPT teams focus their attention on meaningful results during large scans.
Export findings in JSON, CSV, XML and HTML. Generate a technical Developer Report containing evidence, impact, payloads and remediation guidance, or create an Executive Summary for management and stakeholders.
Sessions, requests, responses, findings and tokens are stored locally in a structured SQLite database, giving you a transparent and queryable record of your security assessment.
Work with different access levels using Admin, Analyst and Viewer roles. Audit logging provides visibility into activity when the tool is used by multiple analysts.
The tool uses a Python-based architecture, allowing security teams to extend detection capabilities and build additional testing logic without learning a proprietary plugin SDK.
Capture → Analyze → Verify → Fuzz → Replay → Document
Instead of switching between multiple tools for different stages of an API assessment, Josh API Analyzer brings core API testing capabilities together in one desktop application.
Whether you're performing a penetration test, security assessment, bug bounty research or internal API security review, Josh API Analyzer is designed to make API testing faster and more organized.
Get Josh API AnalyzerAuthorized Testing Only: Josh API Analyzer is intended only for security testing of systems you own or have explicit authorization to assess. Always obtain appropriate permission before performing active security testing.
If these tools don't quite cover your workflow, I also take on custom security tooling and automation as part of consulting engagements.
Get In Touch