Hey everyone! I've been working on a side project called Kurokagi, an open-source security scanner written in Go. It focuses on authorization issues like IDOR, BOLA and BFLA. Basically, checking whether users can access or modify things they shouldn't be able to. I just released the first version (v0.1.0), with support for multiple identities, controlled mutation testing and retesting previous findings. It's still early, and I'm currently the only maintainer. Would love some feedback, especially from anyone interested in Go or API security. Contributions are welcome too! GitHub: https://github.com/aman-sharma-dev/kurokagi Feel free to try it out and tell me what you think, or what I managed to screw up lol.   submitted by   /u/Powerful_Math_2043 [link]   [comments]