
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Automatic SQL injection and database takeover tool

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

Your gateway to OWASP. Discover, engage, and help shape the future!

OWASP Honeypot, Automated Deception Framework.

An easy-to-use and lightweight API wrapper for Censys APIs.

Idempotent functions for IBM Security Appliance REST APIs. Currently covering ISAM and ISDS Appliances.

Knocker, a knock based access control service for your homelab

Rewe API reverse engineering in Go

Frida-based runtime API monitor for Android apps that logs invoked APIs, parameters, return values, and call origins across predefined or custom…

ArmourBird CSF - Container Security Framework

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

HMAC Implementation Example and Explanation