
reverse-engineering-browser
Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Automated HTTP Request Repeating With Burp Suite

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

Caches JWT authentication tokens from an auth URL and attaches them as headers to in-scope requests in Burp Suite for automated session handling.

Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.

HTTP proxy bridge for security testing of remote MCP servers, allowing standard HTTP tools to send JSON-RPC messages and manage sessions.

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

A collaborative web exploitation framework.

OPNsense GUI, API and systems backend

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…