The OWASP ZAP core project
Automated Penetration Testing Agentic Framework Powered by LLMs
The Pentester’s Companion
UFONet - Denial of Service Toolkit
Fully autonomous AI hacker to find actual exploits in your web apps
Modular CLI framework for managing penetration testing tools
Automation framework for reconnaissance and penetration testing tasks
A free and open source interactive HTTPS proxy
Web application fuzzer
The browser exploitation framework project
mitmproxy implemented with golang
Web Debugging Proxy for macOS, iOS, and Android
Scanner detecting the use of JavaScript libraries
HTTP proxy server,support HTTPS & websocket
Directory/File, DNS and VHost busting tool written in Go
Malicious traffic detection system
Security auditing tool for Linux, macOS, and UNIX-based system
CTFs as you need them
The Ray Tracing in One Weekend series of books
Merlin is a cross-platform post-exploitation HTTP/2 Command
A lightweight and powerful iOS framework for intercepting HTTP/HTTPS
Count and limit requests by key with atomic increments
Enable self-service operations, give specific users access
XRay for recon, mapping and OSINT gathering from public networks
High-performance reconnaissance and vulnerability scanning tool