
purpleteam-s2-containers
Stage two containers

Stage two containers

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Web Application Security Scanner Framework

Real-time web application weakness monitoring SDK and scanner. Detects XSS, SQL injection, sensitive payloads, and code vulnerabilities via dynamic…

A curated list of awesome iOS application security resources.

Static and dynamic Android application security analysis

Collaborative application security testing between humans and agents via CLI and MCP

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Some good resources for getting started with application security

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

A lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.


A runtime mobile application analysis toolkit with a Web GUI, powered by Frida, written in Python.