
mcp-xray
Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Automated testing suite with live traffic record and replay

MAPS cloud scanner and response parser for Microsoft Defender research.

Collaborative application security testing between humans and agents via CLI and MCP

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Hermes Proxy - HTTP Traffic Analyzer

The collaborative web app pentest suite

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

Radamsa fuzzer extension for Burp Suite

BurpSuite Standard/Private Collaborator Library

An API hooking framework for intercepting and monitoring Windows applications

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…