
PwnFox
Firefox/Burp extension for security audits with single-click proxy, container profiles, postMessage logging, JS injection toolbox, and security…

Firefox/Burp extension for security audits with single-click proxy, container profiles, postMessage logging, JS injection toolbox, and security…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

Lightweight web proxy for intercepting, inspecting, and modifying HTTP traffic to audit web applications during penetration testing and bug bounty…

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

A compact guide to network pivoting for penetration testings / CTF challenges.

Zap Extension for collaboration in Faraday

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

An HTTP toolkit for security research.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…


The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

💫 Ngrok FRP Alternative • ⚡ Fast • 🪶 Lightweight • 0️⃣ Dependency • 🔌 Pluggable • 😈 TLS interception • 🔒 DNS-over-HTTPS • 🔥 Poor Man's VPN • ⏪…

Hackable HTTP proxy for resiliency testing and simulated network conditions

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…