
iron-proxy
An egress firewall for untrusted workloads.

An egress firewall for untrusted workloads.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Caches JWT authentication tokens from an auth URL and attaches them as headers to in-scope requests in Burp Suite for automated session handling.

Zap Extension for collaboration in Faraday

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

⏰ 🔥 A TCP proxy to simulate network and system conditions for chaos and resiliency testing

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Open-source web application firewall engine with event-based rule language for HTTP traffic monitoring, logging, and real-time attack protection…

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

OPNsense GUI, API and systems backend

Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac 🎉 Open an issue here to…

Fast, lightweight, zero-dependency HTTP/HTTPS proxy server framework with TLS interception, reverse proxy, DNS-over-HTTPS, and plugin-based…

Rogue Wi-Fi access point framework for penetration testing, featuring MITM attacks, DNS spoofing, phishing portals, credential harvesting, and…