
Bug-Bounty-Arsenal-v.3
Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.

WEB SERVICE SECURITY ASSESSMENT TOOL

Collaborative application security testing between humans and agents via CLI and MCP

Mobile Edge-Dynamic Unified Security Analysis

Security profiling for blackbox iOS

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

MAPS cloud scanner and response parser for Microsoft Defender research.

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Main repo for hosting release binaries

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Penetration testing and auditing toolkit for Android apps.

Model Context Protocol server for autonomous vulnerability discovery

The collaborative web app pentest suite

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…