The OWASP ZAP core project
A lightweight and powerful iOS framework for intercepting HTTP/HTTPS
CTFs as you need them
Automatic SQL injection and database takeover tool
Directory/File, DNS and VHost busting tool written in Go
Scanner detecting the use of JavaScript libraries
A collection of Python classes for working with network protocols
Cell-by-cell testing for production Jupyter notebooks in JupyterLab
Easy to use cryptographic framework for data protection
Merlin is a cross-platform post-exploitation HTTP/2 Command
HTTP proxy server,support HTTPS & websocket
C2 framework used to aid red teamers with post-exploitation
CSZ CMS is a open source content management system. With Codeigniter.
Powerful framework for rogue access point attack
Kraken: A multi-platform distributed brute-force password cracking
Vulnerable Pentesting Lab Environment
Lightweight, high-performance, powerful intranet penetration proxy
Extension that allows you to intercept and edit HTTP/HTTPS requests
Full-featured C2 framework which silently persists on webserver
WebSploit is a high level MITM Framework
Offensive Web Testing Framework (OWTF), is a framework
A web proxy in Golang with amazing features
Perform advanced MiTM attacks on websites with ease