
msldap
Python library for auditing Microsoft Active Directory via LDAP, supporting NTLM, Kerberos, SSPI authentication, channel binding, encryption, and…

Python library for auditing Microsoft Active Directory via LDAP, supporting NTLM, Kerberos, SSPI authentication, channel binding, encryption, and…


Mirror moved — see GitHub and Codeberg

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

A proxy for net.tcp-based WCF traffic.

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

SAML2 Burp Extension

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Burp Suite extension to perform Kerberos authentication

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

CyberArk Security Audit

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.