#1Tools for intercepting, analyzing, and modifying web traffic for security testing.
Kitploit recommended

Next Generation SSLKillSwitch with much more support!
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

Powerful framework for rogue access point attack.

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

An open-source, pentest and developer-oriented web browser, using the power of Lua

HTTP/HTTPS proxy over SSH

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

Swiss Army knife for raw bytes manipulation & interception

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

Automated HTTP Request Repeating With Burp Suite

This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, Proxy…

Privaxy is the next generation tracker and advertisement blocker. It blocks ads and trackers by MITMing HTTP(s) traffic. Also check out my new…

Convert Cobalt Strike profiles to modrewrite scripts

Import To Sitemap is a Burp Suite Extension to import wstalker CSV file or ZAP export file into Burp Sitemap

Caches JWT authentication tokens from an auth URL and attaches them as headers to in-scope requests in Burp Suite for automated session handling.

Save the trouble to open the burpsuite...