
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…


Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Android DEX → Java decompiler in Rust, built for speed — full apps in seconds, queries in milliseconds. Progressive analysis, javac-verified output,…

Automatic SQL injection and database takeover tool

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A next-generation crawling and spidering framework.

Web vulnerability scanner written in Python3

A native APK and DEX decompiler written in Rust

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…

Unofficial frida extension for VSCode


Extract the managed (.NET) assemblies out of a MAUI Android assembly store.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…