
api-scanner-docker
Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

WEB SERVICE SECURITY ASSESSMENT TOOL

MAPS cloud scanner and response parser for Microsoft Defender research.

An API hooking framework for intercepting and monitoring Windows applications

Automated testing suite with live traffic record and replay

⚡️ Multiple target ZAP Scanning

Collaborative application security testing between humans and agents via CLI and MCP

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Martian is a library for building custom HTTP/S proxies

PyJFuzz - Python JSON Fuzzer

The AI toolkit for building reliable browser automations

Wireshark for MCP. A transparent proxy between your AI client and MCP server. Watch every call live in your terminal, fail CI on what it finds,…

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.


Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Hermes Proxy - HTTP Traffic Analyzer

Radamsa fuzzer extension for Burp Suite

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library