
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Collaborative application security testing between humans and agents via CLI and MCP

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.


An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Quick n' dirty web/mcp terminal tunneling your phone & pc

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Hermes Proxy - HTTP Traffic Analyzer

bbs is a router for SOCKS and HTTP proxies. It exposes a SOCKS5 (or HTTP CONNECT) service and forwards incoming requests to proxies or chains of…

This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.

The collaborative web app pentest suite

Open-source MITM proxy to intercept, inspect, and mock network traffic.

An HTTP toolkit for security research.

Mirror moved — see GitHub and Codeberg