#1Tools for intercepting, analyzing, and modifying web traffic for security testing.
Kitploit recommended

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Interactive cli tool for HTTP inspection

Proxifier Alternative to redirect any Windows/MacOS/Linux TCP and UDP traffic to HTTP/Socks5 proxy

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

Domain-fronted HTTP/SOCKS5 proxy tunneling traffic through Google Apps Script with MITM TLS interception, HTTP/1-2 multiplexing, and DPI evasion.

Squid Web Proxy Cache - Source Code

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

A Python module to bypass Cloudflare's anti-bot page.

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic


A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

💫 Ngrok FRP Alternative • ⚡ Fast • 🪶 Lightweight • 0️⃣ Dependency • 🔌 Pluggable • 😈 TLS interception • 🔒 DNS-over-HTTPS • 🔥 Poor Man's VPN • ⏪…

A cli tool to proxy and analyze TCP connections.

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.