


Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

Burp Extension for collaboration in Faraday

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

A versatile and portable proxy for capturing, manipulating, and replaying HTTP/HTTPS traffic on the go.

A library for integrating communication channels with the Cobalt Strike External C2 server

Next Generation SSLKillSwitch with much more support!

HTTP/HTTPS proxy over SSH

Burp Suite JS Beautifier

This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.

Ruby In The Middle (HTTP/HTTPS interception proxy)

CLI MITM proxy that converts SOCKS4/SOCKS5 into HTTP/HTTPS/HTTP2/HTTP3 proxy with transparent TCP/UDP redirection, ARP/NDP/DNS spoofing, traffic…

Automated HTTP Request Repeating With Burp Suite


SOCKS5-to-HTTP proxy bridge that tunnels arbitrary TCP streams (SSH, SMTP, TLS) through standard HTTP requests, enabling network traffic obfuscation…

Proof-of-concept exploit for CVE-2025-32407: TLS certificate validation bypass in Samsung Internet for Galaxy Watch, enabling Man-in-the-Middle…

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).