
sandcat
An open-source, pentest and developer-oriented web browser, using the power of Lua

An open-source, pentest and developer-oriented web browser, using the power of Lua

Python script to scan SharePoint hosts for CVE-2025-53770 using custom payloads, with optional Burp Suite proxy interception for traffic analysis and…

Squid Web Proxy Cache - Source Code

A Python module to bypass Cloudflare's anti-bot page.

Burp Plugin to decrypt AES encrypted traffic on the fly

An egress firewall for untrusted workloads.

HTTP/HTTPS proxy in a single python script

A library for integrating communication channels with the Cobalt Strike External C2 server

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

Privacy aware web content sanitizer proxy as a service

Quick n' dirty web/mcp terminal tunneling your phone & pc

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)


Improved decoder for Burp Suite

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

The collaborative web app pentest suite

The world's fastest agentic crawler. Reclaimed. Reinvented. Ready for war.