
TProxer
A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

A Burp Extension designed to identify argument injection vulnerabilities.

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Ruby command-line interface to Burp Suite's REST API

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

Node.js SDK for capturing and replaying API calls made to/from your service

Automated testing suite with live traffic record and replay

Collaborative application security testing between humans and agents via CLI and MCP

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A program for testing WAF functionality

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

HTTP Proxy Analysis for reverse engineering protocol communication

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

API Scraper Agent for Web API's