Tool · intercepting-proxyactive
Hetty
An open-source HTTP toolkit for security research and bug bounty positioned as a Burp Suite alternative. Provides a machine-in-the-middle HTTP proxy with request logging and advanced search, request interception/manipulation, an HTTP client for crafting and replaying requests, scope management, and project-based storage, all driven through a web-based admin interface.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
More tools
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.
- AI Vuln Scannerdast/web-app-scannerA security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.
- Aktoapi-securityOpen-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.
- AmassreconDeep passive subdomain enumeration across many public sources.
- ArjundiscoveryDiscovers hidden HTTP parameters using a bundled (SecLists-upsizable) wordlist.
- assetfinderreconFast passive subdomain discovery drawing on crt.sh, certspotter, hackertarget, threatcrowd and wayback.