
sign-saboteur
SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

The collaborative web app pentest suite

Automate common Chrome Debug Protocol tasks to help debug web applications from the command-line and actively monitor and intercept HTTP requests and…

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…


Web traffic interception simulation tool for cybersecurity research and defensive learning in isolated lab environments.

Privaxy is the next generation tracker and advertisement blocker. It blocks ads and trackers by MITMing HTTP(s) traffic. Also check out my new…

A library for integrating communication channels with the Cobalt Strike External C2 server

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

The world's fastest agentic crawler. Reclaimed. Reinvented. Ready for war.

Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…