
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Modular Android APK security analysis framework integrating static, dynamic, and reverse engineering tools for comprehensive vulnerability assessment…

Penetration testing and auditing toolkit for Android apps.

Customizable Windows-based virtual machine distribution pre-packaged with offensive security tools for penetration testing and red teaming operations.

adaptive agents for dynamic web penetration testing

Frida scripts for mobile application dynamic-analysis.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

FakeNet-NG - Next Generation Dynamic Network Analysis Tool

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.

CVE-2026-39808 - Fortinet Sandbox - Draft

CVE-2026-39813 - Fortinet Sandbox - Draft

Ghidra is a software reverse engineering (SRE) framework

UNIX-like reverse engineering framework and command-line toolset

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Main repo for hosting release binaries

A collection of android security related resources

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…