
ZSC
OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Open-source MITM proxy to intercept, inspect, and mock network traffic.

Ruby command-line interface to Burp Suite's REST API

REST/JSON API to the Burp Suite security tool.

Wireshark for MCP. A transparent proxy between your AI client and MCP server. Watch every call live in your terminal, fail CI on what it finds,…

Automated testing suite with live traffic record and replay

Sample Burp Suite extensions demonstrating the Montoya API, covering HTTP and proxy handlers, custom scan checks, Intruder payloads, WebSocket…

In-depth attack surface mapping and asset discovery

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

The AI toolkit for building reliable browser automations

A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report templates,…

High-performance HTTP/HTTPS/SOCKS5 MITM proxy in Rust with TLS interception, rule-based request rewriting, traffic capture, breakpoints, script…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Node.js SDK for capturing and replaying API calls made to/from your service

Collaborative application security testing between humans and agents via CLI and MCP

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.