Modlishka is a powerful, open-source reverse proxy tool that allows users to intercept and manipulate HTTP traffic, making it an ideal solution for penetration testers, security researchers, and developers to analyze and test web applications. With Modlishka, users can easily set up a reverse proxy server to intercept and modify HTTP requests and responses, enabling them to identify vulnerabilities, test web application security, and develop custom security tools. The tool provides a flexible and customizable framework for building custom proxy servers, making it an essential tool for anyone involved in web application security testing and development.
FEATURES
SIMILAR TOOLS
OWASP OWTF is a penetration testing framework focused on efficiency and alignment with security standards.
A tool for security researchers and penetration testers to automate the process of finding sensitive information on a target domain.
Self-hosted Fuzzing-As-A-Service platform for continuous developer-driven fuzzing.
Using Apache mod_rewrite as a redirector to filter C2 traffic for Cobalt Strike servers.
AzureC2Relay enhances security by validating and relaying Cobalt Strike beacon traffic through Azure Functions.
A tool for generating .NET serialized gadgets for triggering .NET assembly load/execution.
An exploitation framework for industrial security with modules for controlling PLCs and scanning devices.
A collection of Python scripts for password spraying attacks against Lync/S4B & OWA, featuring Atomizer, Vaporizer, Aerosol, and Spindrift tools.
An open-source shellcode and PE packer for creating and managing portable executable files.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.