
ssl-kill-switch2
Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Rust components for traffic interception and redirection, enabling WireGuard device proxying and local app redirection across macOS, Windows, and…

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

The collaborative web app pentest suite

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Hermes Proxy - HTTP Traffic Analyzer

Proof-of-concept exploit for CVE-2025-32407: TLS certificate validation bypass in Samsung Internet for Galaxy Watch, enabling Man-in-the-Middle…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

The new bridge between Burp Suite and Frida!

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

Next Generation SSLKillSwitch with much more support!

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Interact with Frida devices, processes, and scripts directly from your browser.