#1Tools for intercepting, analyzing, and modifying web traffic for security testing.
Kitploit recommended

LinkedIn recon the easy way

A Python module to bypass Cloudflare's anti-bot page.

Proof-of-concept exploit for CVE-2025-32407: TLS certificate validation bypass in Samsung Internet for Galaxy Watch, enabling Man-in-the-Middle…

A tool to migrate Burpsuite HTTP history to Caido

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

💫 Ngrok FRP Alternative • ⚡ Fast • 🪶 Lightweight • 0️⃣ Dependency • 🔌 Pluggable • 😈 TLS interception • 🔒 DNS-over-HTTPS • 🔥 Poor Man's VPN • ⏪…

IPSpinner works as a local proxy that redirects requests through external services.

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Martian is a library for building custom HTTP/S proxies

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

A compact guide to network pivoting for penetration testings / CTF challenges.

Mallet is an intercepting proxy for arbitrary protocols

Burp Suite extension to perform Kerberos authentication

C2 redirector base on caddy

FireProx written in Go

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

This tool downloads, installs, and configures a shiny new copy of Chromium.