
n00bRAT
Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

Burp Suite JS Beautifier

Datajack Proxy allows you to intercept TLS traffic in native x86 applications across platforms


Ruby In The Middle (HTTP/HTTPS interception proxy)

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Collaborative application security testing between humans and agents via CLI and MCP

Hermes Proxy - HTTP Traffic Analyzer

The collaborative web app pentest suite

Automated SSL pinning bypass for any Flutter & Shorebird version — PyGhidra static analysis auto-discovers BoringSSL and generates ready-to-run Frida…

The world's fastest agentic crawler. Reclaimed. Reinvented. Ready for war.

Automate common Chrome Debug Protocol tasks to help debug web applications from the command-line and actively monitor and intercept HTTP requests and…

HTTP Proxy Analysis for reverse engineering protocol communication

Human-friendly Thrift encoder/decoder

BurpSuite Standard/Private Collaborator Library

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…