
Aresius
Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

Martian is a library for building custom HTTP/S proxies

Reproducible BOLA/IDOR PoC against Onlook's tRPC API (CVE-2026-65013), with a 12-step exploit chain, vulnerable and patched Docker targets, and…

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

GraphQL automated security testing toolkit

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

A modern vulnerable web app

Http request smuggling vulnerability scanner

ExtendedMacro - BurpSuite plugin providing extended macro functionality

Hackable HTTP proxy for resiliency testing and simulated network conditions

REST/JSON API to the Burp Suite security tool.

Research on GraphQL from an AppSec point of view.

API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…

An on-path blackbox network traffic security testing tool