🔐 Authentication & Session Testing
This category focuses on tools designed to brute-force web login protocols, dissect and forge JSON Web Tokens (JWT), and map out OAuth authorization flaws.
Tool Catalog
Hydra
A very fast network logon cracker supporting multiple authentication protocols (HTTP, SSH, FTP, Telnet).
Medusa
Speedy, parallel login brute forcer engine supporting modular protocols.
jwt_tool
Toolkit for auditing and exploiting JSON Web Tokens (including signature validation bypasses, None algorithm forgery, and key confusion).
Burp Suite Intruder / Authz
Automated request replay plugins designed to test authentication rate-limiting and authorization boundary violations.