
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
Tools for testing, exploiting, and securing web applications and APIs.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Model Context Protocol server for autonomous vulnerability discovery


PoCs and exploits for CVEs discovered by NebuSec.

XML Security Library

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price…

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor…

Fast CLI tool to scan websites, sitemaps, and URL lists for broken links, with concurrent workers, coverage reporting, and multiple output formats.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…


AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

A modular vulnerability scanner with automatic report generation capabilities.

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…