
httplab
Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Go client to communicate with Chaos DB API.

Automated HTTP Request Repeating With Burp Suite

A wordlist of API names for web application assessments

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

PyJFuzz - Python JSON Fuzzer

The AI toolkit for building reliable browser automations

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Open-source MITM proxy to intercept, inspect, and mock network traffic.

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

Burp Plugin to decrypt AES encrypted traffic on the fly

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.