
shannon
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automatic SQL injection and database takeover tool

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

☸The first ever dependency-aware GraphQL API testing tool!

A rapid HTTP downgrade smuggling scanner written in Go.

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more


Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.