
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Modlishka. Reverse Proxy.

The ZAP Heads Up Display (HUD)

An open-source, pentest and developer-oriented web browser, using the power of Lua

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

An egress firewall for untrusted workloads.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…

A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate…

Interactive cli tool for HTTP inspection

Domain-fronted HTTP/SOCKS5 proxy tunneling traffic through Google Apps Script with MITM TLS interception, HTTP/1-2 multiplexing, and DPI evasion.

Burp Plugin to decrypt AES encrypted traffic on the fly

HTTP/HTTPS proxy over SSH

Browser-based C2 tunnel that exfiltrates payloads through Firefox's cookie.sqlite and auto-submitting HTML/JS, enabling stealthy firewall bypass for…

Burp Commander written in Go