Tests API rate limiting for bypass vulnerabilities using Python (requests/aiohttp) and Burp Suite Turbo Intruder to manipulate headers (e.g. X-Forwarded-For spoofing), IPs, HTTP methods, API versions, and encodings, mapping findings to OWASP API4:2023 Unrestricted Resource Consumption. Use when assessing, under written authorization, whether rate limits can be bypassed to enable brute force or resource-exhaustion attacks.