
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Hermes Proxy - HTTP Traffic Analyzer

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

The collaborative web app pentest suite

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

Web app authorisation coverage scanning

Damn Vulnerable C# Application (API)

Hidden parameters discovery suite

A modern vulnerable web app

An intentionally designed broken web application based on REST API.

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)