
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

OPNsense GUI, API and systems backend

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Datajack Proxy allows you to intercept TLS traffic in native x86 applications across platforms

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

Collaborative application security testing between humans and agents via CLI and MCP

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

Burp Extension for collaboration in Faraday

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

Exploit for Dahua camera authentication bypass (CVE-2021-33045) using mitmproxy to intercept and modify login requests to /RPC2_Login.

Save the trouble to open the burpsuite...

Proof of concept for CVE-2017-6640 as burp extension