
yakit
All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

The collaborative web app pentest suite

Mirror moved — see GitHub and Codeberg

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

An open-source, pentest and developer-oriented web browser, using the power of Lua

Firefox/Burp extension for security audits with single-click proxy, container profiles, postMessage logging, JS injection toolbox, and security…

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.

Ratched is a transparent Man-in-the-Middle TLS proxy intended for penetration testing

Burp Commander written in Go