The OWASP ZAP core project
Automated Penetration Testing Agentic Framework Powered by LLMs
UFONet - Denial of Service Toolkit
Fully autonomous AI hacker to find actual exploits in your web apps
The Pentester’s Companion
Modular CLI framework for managing penetration testing tools
Automation framework for reconnaissance and penetration testing tasks
A free and open source interactive HTTPS proxy
Web application fuzzer
Scanner detecting the use of JavaScript libraries
mitmproxy implemented with golang
Directory/File, DNS and VHost busting tool written in Go
HTTP proxy server,support HTTPS & websocket
CTFs as you need them
The Ray Tracing in One Weekend series of books
A lightweight and powerful iOS framework for intercepting HTTP/HTTPS
Merlin is a cross-platform post-exploitation HTTP/2 Command
Count and limit requests by key with atomic increments
High-performance reconnaissance and vulnerability scanning tool
Enable self-service operations, give specific users access
XRay for recon, mapping and OSINT gathering from public networks
Asset inventory dataset for public bug bounty program targets
Enables in-process caching of secrets for Python applications
Active Directory and Internal Pentest Cheatsheets
A tool to check web apps for vulnerabilty