
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Automatic SQL injection and database takeover tool

Automatic SSTI detection tool with interactive interface

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…


A next-generation crawling and spidering framework.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

A fast, simple, recursive content discovery tool written in Rust.

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Web vulnerability scanner written in Python3

The repo contains a series of challenges for learning Frida for Android Exploitation.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

An strace-like program for the Windows 'native' API

Unofficial frida extension for VSCode