
Mobile-Security-Framework-MobSF
Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

⚡️ Multiple target ZAP Scanning

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Martian is a library for building custom HTTP/S proxies

A lightweight dynamic instrumentation library

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

The AI toolkit for building reliable browser automations

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

WEB SERVICE SECURITY ASSESSMENT TOOL

PyJFuzz - Python JSON Fuzzer

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)


Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Automated testing suite with live traffic record and replay

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…