
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Hooker is an opensource project for dynamic analyses of Android applications. This project provides various tools and applications that can be use to…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

Burp Extension for collaboration in Faraday

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Alexa skill example for Faraday API

Zap Extension for collaboration in Faraday

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)