
toolbox
Collaborative application security testing between humans and agents via CLI and MCP

Collaborative application security testing between humans and agents via CLI and MCP

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

⚡️ Multiple target ZAP Scanning

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Hermes Proxy - HTTP Traffic Analyzer

The AI toolkit for building reliable browser automations

The ZAP Heads Up Display (HUD)

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

An API hooking framework for intercepting and monitoring Windows applications

Automated testing suite with live traffic record and replay

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

MAPS cloud scanner and response parser for Microsoft Defender research.

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Multi-engine DAST scanner aggregating Nikto, ZAP, Nuclei, SkipFish, and Wapiti for automated web injection vulnerability detection with consolidated…

Martian is a library for building custom HTTP/S proxies

PyJFuzz - Python JSON Fuzzer