The OWASP ZAP core project
Automated Penetration Testing Agentic Framework Powered by LLMs
Modular CLI framework for managing penetration testing tools
The Pentester’s Companion
UFONet - Denial of Service Toolkit
Automation framework for reconnaissance and penetration testing tasks
Fully autonomous AI hacker to find actual exploits in your web apps
Web application fuzzer
A free and open source interactive HTTPS proxy
The browser exploitation framework project
Directory/File, DNS and VHost busting tool written in Go
Scanner detecting the use of JavaScript libraries
mitmproxy implemented with golang
Security auditing tool for Linux, macOS, and UNIX-based system
HTTP proxy server,support HTTPS & websocket
Malicious traffic detection system
The Ray Tracing in One Weekend series of books
A lightweight and powerful iOS framework for intercepting HTTP/HTTPS
CTFs as you need them
Merlin is a cross-platform post-exploitation HTTP/2 Command
XRay for recon, mapping and OSINT gathering from public networks
Count and limit requests by key with atomic increments
Enable self-service operations, give specific users access
High-performance reconnaissance and vulnerability scanning tool
Asset inventory dataset for public bug bounty program targets