
gori
A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

A Burp Extension designed to identify argument injection vulnerabilities.

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

Collaborative application security testing between humans and agents via CLI and MCP

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

Discover hidden parameters in Caido

MAPS cloud scanner and response parser for Microsoft Defender research.

The collaborative web app pentest suite

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

HTTP Proxy Analysis for reverse engineering protocol communication

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

find sensitive data leaking from ServiceNow instances.