
ssrf-king
SSRF plugin for burp Automates SSRF Detection in all of the Request

SSRF plugin for burp Automates SSRF Detection in all of the Request

An strace-like program for the Windows 'native' API

Open-source adversary emulation for AI agents and MCP servers.

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

Node.js SDK for capturing and replaying API calls made to/from your service

Executable security regression testing for agentic applications and MCP-integrated systems.

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…