
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Python proof-of-concept exploit for CVE-2025-32375 in BentoML, demonstrating and validating the vulnerability against affected deployments.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Web vulnerability scanner written in Python3

AI-powered bug bounty hunting toolkit that works with or without subscription.


Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automatic SQL injection and database takeover tool

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Burp Commander written in Go

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

A rapid HTTP downgrade smuggling scanner written in Go.

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…