#1Tools for intercepting, analyzing, and modifying web traffic for security testing.
Kitploit recommended

Python Exploitation Framework, V8 Engine Debugger, Proxy interceptor, marketplace, post-exploitation, backdoor generator,....

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Automated SSL pinning bypass for any Flutter & Shorebird version — PyGhidra static analysis auto-discovers BoringSSL and generates ready-to-run Frida…

Squid Web Proxy Cache - Source Code

Fast TCP/UDP tunnel over HTTP with SSH encryption, supporting reverse port forwarding, SOCKS5 proxy, and client authentication for secure network…

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more…

Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

An egress firewall for untrusted workloads.

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

:alarm_clock: :fire: A TCP proxy to simulate network and system conditions for chaos and resiliency testing

Hermes Proxy - HTTP Traffic Analyzer

An HTTP client specifically developed for security researchers

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution