
Mobile-Security-Framework-MobSF
Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

⚡️ Multiple target ZAP Scanning

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Martian is a library for building custom HTTP/S proxies

The AI toolkit for building reliable browser automations

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

WEB SERVICE SECURITY ASSESSMENT TOOL

PyJFuzz - Python JSON Fuzzer


Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Some good resources for getting started with application security

Automated testing suite with live traffic record and replay

MAPS cloud scanner and response parser for Microsoft Defender research.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Hermes Proxy - HTTP Traffic Analyzer