
hoverfly
Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

The AI toolkit for building reliable browser automations

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Open-source MITM proxy to intercept, inspect, and mock network traffic.

Automated testing suite with live traffic record and replay

A Burp Extension designed to identify argument injection vulnerabilities.

Node.js SDK for capturing and replaying API calls made to/from your service

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Ruby command-line interface to Burp Suite's REST API

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A program for testing WAF functionality

Collaborative application security testing between humans and agents via CLI and MCP