
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

A collection of awesome penetration testing resources, tools and other shiny things

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

autonomous red teaming platform; multi-agent offensive-security meta-harness

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Curated security mind maps covering bug bounty methodology, web app pentesting, recon, red teaming, and defensive security for practitioners.

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Proof-of-concept exploit for CVE-2019-6447 in ES File Explorer, enabling local network attackers to extract device info, files, and launch apps via…

Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across…

Collection of proof-of-concept exploits covering local and remote code execution, privilege escalation, web application flaws, and mobile/embedded…

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

Burp Plugin to decrypt AES encrypted traffic on the fly

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp)

Proof-of-concept exploit for Apple SSL/TLS verification vulnerability (CVE-2014-1266) in iOS and OS X, demonstrating HTTPS interception via a proxy…

Intentionally vulnerable Android banking app for practicing mobile security testing. Covers OWASP Mobile Top 10 with hardcoded credentials, insecure…

Android deeplink misconfiguration detector and exploitation tool

Proof-of-concept exploit for CVE-2016-1764 demonstrating XSS in Apple's OS X iMessage client to recover plaintext chat history and attachments via…