Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.
The Black Hat Bash book repository
graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.
The Black Hat GraphQL Book Repository
Security Auditor Utility for GraphQL APIs