#1Tools for intercepting, analyzing, and modifying web traffic for security testing.
Kitploit recommended

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.
Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

An open-source, pentest and developer-oriented web browser, using the power of Lua

Open-source MITM proxy to intercept, inspect, and mock network traffic.

Privacy aware web content sanitizer proxy as a service

BinProxy is a proxy for arbitrary TCP connections. You can define custom message formats using the BinData gem.

Multi-language web CGI interfaces exploits.

This tool downloads, installs, and configures a shiny new copy of Chromium.

A little bit less hackish way to intercept and modify non-HTTP protocols through Burp & others.

HTTP/HTTPS proxy over SSH

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…

Mallet is an intercepting proxy for arbitrary protocols

CobaltStrike External C2 for Websockets

Quick n' dirty web/mcp terminal tunneling your phone & pc

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.