
black-widow
GUI based offensive penetration testing tool (Open Source)

GUI based offensive penetration testing tool (Open Source)

Browser extension for HTTP/WebSocket traffic capture, interception, modification, replay, and fuzzing with AI-assisted analysis and rule-based…

Desktop HTTP/HTTPS interception proxy with live traffic capture, request replay, HAR import/export, and a rules engine for delaying, overriding, or…

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

High-performance POSIX socket library with TCP/UDP/Unix, TLS 1.3, DTLS, QUIC, HTTP/1.1/2, WebSocket, DNS-over-TLS/HTTPS, async I/O, and security…

Isolated educational lab simulating CVE-2025-4679 OAuth credential exposure. Learn offensive and defensive security through hands-on exercises,…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

🔎Sniffing and parsing mysql,redis,http,mongodb etc protocol. 抓包截取项目中的数据库请求并解析成相应的语句。

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Encrypted peer-to-peer mesh VPN for remote mobile forensics, enabling wireless ADB and libimobiledevice acquisition, network monitoring, and…

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

Proof-of-concept exploit for CVE-2025-32407: TLS certificate validation bypass in Samsung Internet for Galaxy Watch, enabling Man-in-the-Middle…