
reburp
A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Alexa skill example for Faraday API

Burp Extension for collaboration in Faraday

Zap Extension for collaboration in Faraday

Scanner: CVE-2026-42208 LiteLLM SQL Injection — Python scanner for BerriAI LiteLLM proxy instances

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…