
discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

WEB SERVICE SECURITY ASSESSMENT TOOL

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Web vulnerability scanner written in Python3

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

The AI toolkit for building reliable browser automations

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Burp Suite Extension useful to verify OAUTHv2 and OpenID security