
mallory
HTTP/HTTPS proxy over SSH

HTTP/HTTPS proxy over SSH

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Modlishka. Reverse Proxy.

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Lightweight web proxy for intercepting, inspecting, and modifying HTTP traffic to audit web applications during penetration testing and bug bounty…

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

Squid Web Proxy Cache - Source Code

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A starttls-capable transparent man-in-the-middle proxy

Windows Remote Administration Tool via Telegram

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens
