
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Collaborative application security testing between humans and agents via CLI and MCP

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Quick n' dirty web/mcp terminal tunneling your phone & pc

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Hermes Proxy - HTTP Traffic Analyzer

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and…

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…