
mcpsnoop
Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

Hermes Proxy - HTTP Traffic Analyzer

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

Burp Suite JS Beautifier

Martian is a library for building custom HTTP/S proxies

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

HTTP Proxy Analysis for reverse engineering protocol communication

Collaborative application security testing between humans and agents via CLI and MCP

BurpSuite Standard/Private Collaborator Library

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

Ruby In The Middle (HTTP/HTTPS interception proxy)

The collaborative web app pentest suite

Go-based MITM HTTP/HTTPS proxy with HTTP/2 and HTTP/1.1 interception, local CA/per-host cert generation, CONNECT/WebSocket tunneling, disk caching,…