An HTTP/HTTPS intercept proxy written in Go.
-
Updated
Feb 11, 2022 - Go
An HTTP/HTTPS intercept proxy written in Go.
A dotnet tool to do a http request/response security assessment
Learn Spring Security step by step
A scan of all .gov.uk sites for the most common security headers or lack of
OSINT tools for website research
A Python-based HTTP security header analyzer that identifies weak or missing policies (CSP, HSTS, XFO, etc.) and generates OWASP-aligned remediation reports.
Adds missing HTTP response headers to SvelteKit apps
Real-time Layer 7 DDoS detection and HTTP traffic analysis tool designed to identify bot activity, anomalous requests, and application-layer attacks with high accuracy.
Analyze HTTP security headers for your web application. A-F grading, per-header findings, and remediation — as a library or CLI.
Configurable, production-ready security headers middleware for Laravel, with CSP, HSTS, Permissions-Policy, safe defaults, validation, and comprehensive tests.
CLTEcho is an advanced HTTP Request Smuggling detection suite featuring AI-powered analysis, concurrent scanning, and comprehensive reporting. With 6 threat detection types, ML-based anomaly detection, HTTP/2 support, and WAF bypass techniques, it delivers enterprise-grade security testing with professional HTML/JSON reports for security researcher
Advanced Network Reconnaissance & Vulnerability Assessment CLI Tool
Overkill Bash tool to scan and rate HTTP security headers (CSP, HSTS, COOP, CORP, Permissions-Policy + more). Passive, fast, nuclear edition by MR.Thugh ☠
A Python-based web vulnerability scanner that analyzes HTTP security headers, detects security configuration weaknesses, performs risk assessment, and generates automated security reports for cybersecurity learning and Blue Team practice.
Issue tracker microservice project
Structured evidence capture for bug bounty and pentest reports — collect reproducible web vulnerability proof offline.
Discover API endpoints from JS bundles, HAR, OpenAPI, and sitemaps — build offline API attack-surface inventories for pentests.
Parse Content-Security-Policy — flag unsafe-inline, unsafe-eval, missing directives, and CSP bypass risks for XSS defense.
Anonymous message board microservice project
To associate your repository with the http-security topic, visit your repo's landing page and select "manage topics."