
zap-hud
In-browser interface for OWASP ZAP that provides real-time web security testing, including active scanning, interception, and vulnerability…

In-browser interface for OWASP ZAP that provides real-time web security testing, including active scanning, interception, and vulnerability…

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers


Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

Automated HTTP Request Repeating With Burp Suite

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Burp Plugin to decrypt AES encrypted traffic on the fly

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Open-source MITM proxy to intercept, inspect, and mock network traffic.

Collaborative application security testing between humans and agents via CLI and MCP

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

Desktop HTTP/HTTPS interception proxy with live traffic capture, request replay, HAR import/export, and a rules engine for delaying, overriding, or…

A Burp Extender plugin, that will make binary soap objects readable and modifiable.

Go-based CLI client for BurpSuite REST API, enabling automated scanning, proxy control, and task management for penetration testing workflows.

This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, Proxy…