
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Python proof-of-concept exploit for CVE-2025-32375 in BentoML, demonstrating and validating the vulnerability against affected deployments.

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

Web vulnerability scanner written in Python3


An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Automatic SQL injection and database takeover tool

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Alexa skill example for Faraday API

Node.js SDK for capturing and replaying API calls made to/from your service