
gori
A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Hidden parameters discovery suite

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Ruby command-line interface to Burp Suite's REST API

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

Collaborative application security testing between humans and agents via CLI and MCP

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A program for testing WAF functionality

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

Hermes Proxy - HTTP Traffic Analyzer

Discover hidden parameters in Caido

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.