
Bug-Bounty-Arsenal-v.3
Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.

The world's fastest agentic crawler. Reclaimed. Reinvented. Ready for war.

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

Security profiling for blackbox iOS

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

Collaborative application security testing between humans and agents via CLI and MCP

WEB SERVICE SECURITY ASSESSMENT TOOL

The AI toolkit for building reliable browser automations

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

MAPS cloud scanner and response parser for Microsoft Defender research.

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

The collaborative web app pentest suite

A Linux Host-based Intrusion Detection System based on eBPF.

Main repo for hosting release binaries