
evilwaf
evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Quick and Simple Scripts to Scan for Vulnerable Servers and Packet Level Monitors

HTTP Proxy Analysis for reverse engineering protocol communication

Interact with Frida devices, processes, and scripts directly from your browser.

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.

Datajack Proxy allows you to intercept TLS traffic in native x86 applications across platforms

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

REST/JSON API to the Burp Suite security tool.

Windows Remote Administration Tool via Telegram

Modlishka. Reverse Proxy.

Quick n' dirty web/mcp terminal tunneling your phone & pc

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Extension adds a new tab in Burp Suite called Extractor

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…