
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida,…

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic

Frida toolkit that bypasses SSL/TLS certificate pinning on Android apps, hooking Java TrustManager, OkHttp, Conscrypt, and native OpenSSL/BoringSSL…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Persists BurpSuite proxy history, Repeater requests, and Intruder payloads across sessions; exports and imports .log files for web pentesting context.

An HTTP toolkit for security research.

Lightweight web proxy for intercepting, inspecting, and modifying HTTP traffic to audit web applications during penetration testing and bug bounty…

A compact guide to network pivoting for penetration testings / CTF challenges.

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Scripts to clone CA certificates for use in HTTPS client attacks.

Burp Extension for collaboration in Faraday

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Zap Extension for collaboration in Faraday

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI