
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Automatic SQL injection and database takeover tool

Automatic SSTI detection tool with interactive interface

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…


A next-generation crawling and spidering framework.

A fast, simple, recursive content discovery tool written in Rust.

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Web vulnerability scanner written in Python3

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

The repo contains a series of challenges for learning Frida for Android Exploitation.

Scriptable debugger for Android Dalvik VM using JDWP/DDM interfaces to hook methods, inspect process state, and modify runtime behavior without…