

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

OAuth Request Crafter

REST/JSON API to the Burp Suite security tool.

HTTP/HTTPS proxy over SSH

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Scripts to clone CA certificates for use in HTTPS client attacks.

HTTP/HTTPS MITM proxy and recorder.


SOCKS5-to-HTTP proxy bridge that tunnels arbitrary TCP streams (SSH, SMTP, TLS) through standard HTTP requests, enabling network traffic obfuscation…

HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox