
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Python proof-of-concept exploit for CVE-2025-32375 in BentoML, demonstrating and validating the vulnerability against affected deployments.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

Web vulnerability scanner written in Python3

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

AI-powered bug bounty hunting toolkit that works with or without subscription.


AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

Automatic SQL injection and database takeover tool

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.