The OWASP ZAP core project
Automated Penetration Testing Agentic Framework Powered by LLMs
Modular CLI framework for managing penetration testing tools
The Pentester’s Companion
UFONet - Denial of Service Toolkit
Automation framework for reconnaissance and penetration testing tasks
Fully autonomous AI hacker to find actual exploits in your web apps
Web application fuzzer
A free and open source interactive HTTPS proxy
The browser exploitation framework project
Web Debugging Proxy for macOS, iOS, and Android
Scanner detecting the use of JavaScript libraries
Security auditing tool for Linux, macOS, and UNIX-based system
mitmproxy implemented with golang
The Ray Tracing in One Weekend series of books
HTTP proxy server,support HTTPS & websocket
A lightweight and powerful iOS framework for intercepting HTTP/HTTPS
CTFs as you need them
Merlin is a cross-platform post-exploitation HTTP/2 Command
XRay for recon, mapping and OSINT gathering from public networks
Count and limit requests by key with atomic increments
Enable self-service operations, give specific users access
High-performance reconnaissance and vulnerability scanning tool
Asset inventory dataset for public bug bounty program targets
OSINT fuzzing tool using Google dorks to find exposed resources