
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Martian is a library for building custom HTTP/S proxies

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

⚡️ Multiple target ZAP Scanning

Hermes Proxy - HTTP Traffic Analyzer

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

The AI toolkit for building reliable browser automations

PyJFuzz - Python JSON Fuzzer

WEB SERVICE SECURITY ASSESSMENT TOOL


Automated testing suite with live traffic record and replay

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Collaborative application security testing between humans and agents via CLI and MCP

MAPS cloud scanner and response parser for Microsoft Defender research.

Radamsa fuzzer extension for Burp Suite

BurpSuite Standard/Private Collaborator Library

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

An API hooking framework for intercepting and monitoring Windows applications