
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS

The Swiss Army knife for automated Web Application Testing

Proof-of-Concept exploit of CVE-2018-19131: Squid Proxy XSS via X.509 Certificate

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

🤖 A CLI application that automatically prepares Android APK files for HTTPS inspection

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Detect and bypass web application firewalls and protection systems

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

HackBar plugin for Burpsuite

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

A wordlist of API names for web application assessments

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.