
hoverfly
Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Collection of humorous shell scripts automating personal tasks: texting late-work alerts, scanning emails for keywords, faking sick days, and brewing…

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Collection of humorous shell scripts automating personal tasks: texting late-work alerts, scanning emails for keywords, faking sick days, and brewing…

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…


66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit…

Extracts and parses malware family configuration data from CAPE sandbox artifacts, including C2 URLs, botnet IDs, DGA seeds, mutexes, and encryption…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

The open-source wireless research platform for ESP32.

Labtainers: A Docker-based cyber lab framework

Tool for embedding payloads into JPG/PNG format images, allowing to perform certain actions when opening them.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Http proxy to intercept, analyze, and modify traffic

A collection of vulnerabilities & exploits against modern GCS

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…