We can manually fuzz SOAP services, web sockets, GraphQL and protobufs. However, manual effort is time-consuming, and many orgs have a lot of ground to cover. Microsoft has been maintaining RESTler for a number of years, but it relies on generating a proprietary grammar file from an openAPI spec. What other tools are available to make fuzzing these interfaces possible, automatable, and repeatable? Where is further effort needed?
Host Jason Gillam with Mic Whitehorn