
WebGoat
Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

AzureGoat : A Damn Vulnerable Azure Infrastructure

GCPGoat : A Damn Vulnerable GCP Infrastructure

Apache Real Time Logs Analyzer System

A Security Tool for Enumerating WebSockets

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Advanced HTTP fingerprinting PoC

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Web vulnerability scanner written in Python3

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…