
sandcat
An open-source, pentest and developer-oriented web browser, using the power of Lua

An open-source, pentest and developer-oriented web browser, using the power of Lua

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

HTTP/HTTPS MITM proxy and recorder.



BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

Mirror moved — see GitHub and Codeberg

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

Import To Sitemap is a Burp Suite Extension to import wstalker CSV file or ZAP export file into Burp Sitemap

Python script to scan SharePoint hosts for CVE-2025-53770 using custom payloads, with optional Burp Suite proxy interception for traffic analysis and…