The OWASP ZAP core project
Automated Penetration Testing Agentic Framework Powered by LLMs
The Pentester’s Companion
Modular CLI framework for managing penetration testing tools
UFONet - Denial of Service Toolkit
Automation framework for reconnaissance and penetration testing tasks
Web application fuzzer
Fully autonomous AI hacker to find actual exploits in your web apps
A free and open source interactive HTTPS proxy
Scanner detecting the use of JavaScript libraries
Directory/File, DNS and VHost busting tool written in Go
HTTP proxy server,support HTTPS & websocket
The Ray Tracing in One Weekend series of books
A lightweight and powerful iOS framework for intercepting HTTP/HTTPS
CTFs as you need them
mitmproxy implemented with golang
Merlin is a cross-platform post-exploitation HTTP/2 Command
XRay for recon, mapping and OSINT gathering from public networks
Count and limit requests by key with atomic increments
Enable self-service operations, give specific users access
High-performance reconnaissance and vulnerability scanning tool
Asset inventory dataset for public bug bounty program targets
Active Directory and Internal Pentest Cheatsheets
Enables in-process caching of secrets for Python applications
A tool to check web apps for vulnerabilty