

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens


Web vulnerability scanner written in Python3

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Multi-threaded web fuzzer for URL path, HTTP header, and POST data brute-forcing with proxy support, status code filtering, and reflexive content…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

☸The first ever dependency-aware GraphQL API testing tool!

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.

A rapid HTTP downgrade smuggling scanner written in Go.

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…