
hoverfly
Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

SAML2 Burp Extension

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Rust-powered HTTP Request Smuggling Scanner.


A Burp Extension designed to identify argument injection vulnerabilities.

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions


Burp Extension for collaboration in Faraday

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.


Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.