
martian
Martian is a library for building custom HTTP/S proxies

a dart package to analyze CVE-2025-55182 react2shell

Automated testing suite with live traffic record and replay

eBPF-based toolkit for sniffing network traffic, extracting OpenSSL TLS keys, and intercepting/decrypting TLS 1.2 connections in real time using…

Hermes Proxy - HTTP Traffic Analyzer

Windows named pipe hooking toolkit

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Ruby In The Middle (HTTP/HTTPS interception proxy)

Agent-based JMX access via JSON/HTTP with bulk requests, fine-grained security policies, and proxy mode for remote MBeanServer monitoring and…

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

The collaborative web app pentest suite

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

WEB SERVICE SECURITY ASSESSMENT TOOL

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Frida-based in-process fuzzing suite with AFL++ proxy, standalone active/passive modes, and shared memory communication for high-performance…

A Burp Suite extension that integrates Dalfox XSS scanner directly into your workflow.