
masq
Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice


AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

find sensitive data leaking from ServiceNow instances.

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

A fast WordPress plugin enumeration tool

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…


Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Go client to communicate with Chaos DB API.

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

The collaborative web app pentest suite

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

NSE script to check if app is vulnerable to cve-2023-22515