
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Lightweight web proxy for intercepting, inspecting, and modifying HTTP traffic to audit web applications during penetration testing and bug bounty…

Mirror moved — see GitHub and Codeberg

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

The new bridge between Burp Suite and Frida!

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Interact with Frida devices, processes, and scripts directly from your browser.

Frida toolkit that bypasses SSL/TLS certificate pinning on Android apps, hooking Java TrustManager, OkHttp, Conscrypt, and native OpenSSL/BoringSSL…

Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

Root an Android Studio emulator by patching its ramdisk with Magisk — in pure Go.

AI-native penetration testing IDE where operators and an AI agent share browser, terminals, traffic capture, shells, asset graph, tasks, and evidence…

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

Firefox/Burp extension for security audits with single-click proxy, container profiles, postMessage logging, JS injection toolbox, and security…

This tool downloads, installs, and configures a shiny new copy of Chromium.

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.