
porch-pirate
Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

DejaVU - Open Source Deception Framework

A framework for BREACH and other compression-based crypto attacks

Labtainers: A Docker-based cyber lab framework


YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

A blazing fast and fully configurable Blind SQL Injection optimization and automation framework.

A blind XSS detection and XSS data capture framework

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

An modular asset discovery framework written in python to automate the repeating manual work

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

extensible exploitation framework shipped on a modular multi-tasking architecture