Alternatives
Products that do what ExploitSpec does
Turn proven HTTP exploits into permanent regression tests
- 1

- 2HM
2019 · httptoolkit.tech
- 3

- 4AS
2014 · github.com
- 5

- 6OC
2018 · picheta.me
- 7HI
This is based on an approach I made for a very high performance message and video multiplexing server. The project died, but I'm glad I get to share the a basic version with some http test code now. I admit this is the second time I've tried to show this off here today; I posted earlier but it got lost when no-one was watching :(
2011 · github.com
- 8AI
2017 · abtest.io
- 9

- 10

Proves vulnerabilities before reporting them.
8d ago · dashboard-seven-self-13.vercel.app
- 11FC
2015 · github.com
- 12

- 13PA
Hi HN! After several months of work, I'm excited to share ProKZee, a free and open-source network security tool built with Go and React using Wails framework. ProKZee allows developers, security researchers, and penetration testers to intercept, inspect, and modify HTTP/S traffic — similar to tools like Burp Suite, OWASP ZAP, and Caido — but with a fast native UI, modern UX, and some unique features. https://github.com/al-sultani/prokzee
2025 · github.com
- 14BD
2015 · scan.patrolserver.com
- 15AC
2017 · github.com
- 16AS
Free and instant penetration testing for rest APIs. Please try and let me know what do you think? https://www.apisec.ai/free-api-pen-test
2022
- 17

- 18

- 19TA
2016 · github.com
- 20AC
2023 · github.com
- 21BG
We originally set out to solve complex debugging headaches and useless alerts caused by traditional security scanners in our own projects. Static Analysis (SAST) flagged too much noise because it couldn't verify runtime context, while Dynamic Analysis (DAST) missed internal logic bugs because it treated the app like a black box. We built a CLI tool to bridge this gap using grey box testing from a red team approach. We use internal knowledge of the codebase to guide parallel execution, allowing us to find complex or hidden logic errors and attack paths standard linters/scanners miss. The…
Dec 2025 · bloodhoundsecurity.ca
- 22CF
A few months ago, a friend asked me to check his WordPress site for vulnerabilities. What I found shocked me – critical flaws exposing sensitive data everywhere. That's why I built CR4SH3R: a focused tool to detect Arbitrary File Download flaws before attackers do Key Features: Lightning-fast multi-threaded scanning, Extracts credentials from exposed files (like wp-config.php), Generates actionable Excel reports, Simple GUI for one-click security checks Would love your feedback!
2025 · github.com
- 23AO
Remote Code Oxidation is a collection of tools that help offensive security professionals quickly adapt payloads to the needs of their engagement. Any and all feedback is welcome!
2022 · github.com
- 24OA
2015 · proc.link
Ranked by how close each launch is in meaning, then by votes. Refine with a description →