
waf-tester
A program for testing WAF functionality

A program for testing WAF functionality

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Go-based MITM HTTP/HTTPS proxy with HTTP/2 and HTTP/1.1 interception, local CA/per-host cert generation, CONNECT/WebSocket tunneling, disk caching,…

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

The code for personally reproducing the corresponding vulnerability

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

a Damn Vulnerable Serverless Application

An intentionally designed broken web application based on REST API.

Official Elastic Skills

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.