
oproxy
Open-source MITM proxy to intercept, inspect, and mock network traffic.

Open-source MITM proxy to intercept, inspect, and mock network traffic.

SAML2 Burp Extension

Damn Vulnerable C# Application (API)

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Hidden parameters discovery suite

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

⚡️ Multiple target ZAP Scanning

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Hermes Proxy - HTTP Traffic Analyzer

The collaborative web app pentest suite

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.