
tusk-cli
Automated testing suite with live traffic record and replay

Automated testing suite with live traffic record and replay

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

The new bridge between Burp Suite and Frida!

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Collaborative application security testing between humans and agents via CLI and MCP

The collaborative web app pentest suite

Radamsa fuzzer extension for Burp Suite

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Martian is a library for building custom HTTP/S proxies

Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

The AI toolkit for building reliable browser automations