
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

The ZAP Heads Up Display (HUD)

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

A customizable HTTP/HTTPS proxy library for Go supporting regular forwarding, CONNECT tunneling, MITM TLS interception, and programmatic…

A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate…

Burp Plugin to decrypt AES encrypted traffic on the fly

The new bridge between Burp Suite and Frida!

Netcat with automated NAT traversal, secure P2P, and advanced features for shell access, file transfer, and network proxying.

A compact guide to network pivoting for penetration testings / CTF challenges.

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

Frida toolkit that bypasses SSL/TLS certificate pinning on Android apps, hooking Java TrustManager, OkHttp, Conscrypt, and native OpenSSL/BoringSSL…

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

HTTP/HTTPS proxy in a single python script

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Proxifier Alternative to redirect any Windows/MacOS/Linux TCP and UDP traffic to HTTP/Socks5 proxy