#1Tools for intercepting, analyzing, and modifying web traffic for security testing.
Kitploit recommended

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Domain-fronted HTTP/SOCKS5 proxy tunneling traffic through Google Apps Script with MITM TLS interception, HTTP/1-2 multiplexing, and DPI evasion.

An HTTP toolkit for security research.

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

Martian is a library for building custom HTTP/S proxies

REST/JSON API to the Burp Suite security tool.

Windows Remote Administration Tool via Telegram

ExtendedMacro - BurpSuite plugin providing extended macro functionality

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation

Browser-based C2 tunnel that exfiltrates payloads through Firefox's cookie.sqlite and auto-submitting HTML/JS, enabling stealthy firewall bypass for…

Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite

Hackable HTTP proxy for resiliency testing and simulated network conditions

👻 A LAN dropbox chatbot controllable via Telegram

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

DEPRECATED, bettercap developement moved here: https://github.com/bettercap/bettercap

DEPRECATED, wifipumpkin3 -> https://github.com/P0cL4bs/wifipumpkin3