
oproxy
Open-source MITM proxy to intercept, inspect, and mock network traffic.

Open-source MITM proxy to intercept, inspect, and mock network traffic.

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.


A Burp Extension designed to identify argument injection vulnerabilities.

Automated testing suite with live traffic record and replay

Node.js SDK for capturing and replaying API calls made to/from your service

Ruby command-line interface to Burp Suite's REST API

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Collaborative application security testing between humans and agents via CLI and MCP

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

A program for testing WAF functionality

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

HTTP Proxy Analysis for reverse engineering protocol communication

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

API Scraper Agent for Web API's