
PwnFox
Firefox/Burp extension for security audits with single-click proxy, container profiles, postMessage logging, JS injection toolbox, and security…

Firefox/Burp extension for security audits with single-click proxy, container profiles, postMessage logging, JS injection toolbox, and security…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

⚡️ Multiple target ZAP Scanning

cSploit - The most complete and advanced IT security professional toolkit on Android.

Automated Security Testing For REST API's

Lightweight web proxy for intercepting, inspecting, and modifying HTTP traffic to audit web applications during penetration testing and bug bounty…

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

ChatGPT Plus/Team/Pro 订阅协议端到端重放工具集 · hCaptcha 视觉求解器 · 反欺诈机制实证研究 / End-to-end protocol replay toolkit for ChatGPT Plus/Team/Pro subscription with…

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

SSRF plugin for burp Automates SSRF Detection in all of the Request

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Proof-of-Concept exploit of CVE-2018-19131: Squid Proxy XSS via X.509 Certificate

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…