The OWASP ZAP core project
A lightweight and powerful iOS framework for intercepting HTTP/HTTPS
CTFs as you need them
Directory/File, DNS and VHost busting tool written in Go
Automatic SQL injection and database takeover tool
Scanner detecting the use of JavaScript libraries
Web Debugging Proxy for macOS, iOS, and Android
Merlin is a cross-platform post-exploitation HTTP/2 Command
HTTP proxy server,support HTTPS & websocket
Cell-by-cell testing for production Jupyter notebooks in JupyterLab
Easy to use cryptographic framework for data protection
A collection of Python classes for working with network protocols
C2 framework used to aid red teamers with post-exploitation
A tool to check web apps for vulnerabilty
Powerful framework for rogue access point attack
CSZ CMS is a open source content management system. With Codeigniter.
Tiny and obfuscated ASP.NET webshell for C# web applications
Kraken: A multi-platform distributed brute-force password cracking
Vulnerable Pentesting Lab Environment
Lightweight, high-performance, powerful intranet penetration proxy
Extension that allows you to intercept and edit HTTP/HTTPS requests
Full-featured C2 framework which silently persists on webserver
WebSploit is a high level MITM Framework