Burp Suite Professional costs 475 dollars a year per seat.
A senior software engineer in Amsterdam built the open source replacement as a side project. He put it on GitHub for free. It has 10,569 stars.
His name is David Stotijn. The software is Hetty.
Here is what Hetty is.
An HTTP toolkit for security research. A machine-in-the-middle proxy that sits between your browser and the target. Every request and every response flows through Hetty. You can read them, search them, intercept them, edit them, replay them, and send them again.
This is the core loop of every web application security test ever performed. Burp Suite charges 475 dollars a year for it. Hetty does the same job for zero.
Here is the feature set.
A machine-in-the-middle HTTP proxy with full logs and advanced search. An HTTP client for manually creating and editing requests, and replaying any request you already proxied. Request and response interception for manual review, with full edit, send, receive, and cancel control. Scope support to keep your work organized to a single target. A web-based admin interface that runs in your browser. Project-based database storage so multiple engagements stay separate. A GraphQL service for programmatic access.
The installer is a single Go binary. Works on macOS, Linux, and Windows. No Java runtime, no enterprise license server, no machine fingerprinting, no telemetry.
Here is the price ladder.
Burp Suite Professional: 475 dollars a year per seat.
Burp Suite Enterprise: thousands per year, contact sales for a quote.
Burp Suite Community Edition: free, but throttled, no scanner, no project save, no intruder rate.
OWASP ZAP: free and open source, now owned by Checkmarx after a 2024 acquisition.
Hetty: zero. Forever. One binary. No account.
A pentester working full time pays Burp 475 dollars a year. A team of 10 pentesters pays 4,750 dollars a year. A bug bounty hunter who finds one vulnerability has already paid for Burp twice over.
Or they download a 30 MB Go binary written by a freelancer in Amsterdam and keep every dollar they earn.
David has not pushed a new commit in 16 months. The last commit was January 13, 2025. That is normal for a tool that is feature-complete. HTTP has not changed. The proxy still proxies. The intercept still intercepts. MIT licensed code does not expire when the maintainer takes a break.
Buy a domain. Find a bug. Cash a bounty.
PortSwigger took a free industry tool and put it behind a 475 dollar paywall. A freelancer in Amsterdam gave it back. On every platform. For zero dollars.
Your proxy. Your binary. Your bounties.
(Link in the comments)
¿Sabes todo lo que se puede encontrar de ti en internet en 5 minutos?
Dominios. IPs. Wallets cripto. Perfiles sociales. Emails. Relaciones entre todo eso.
Alguien publicó en GitHub la herramienta para verlo como un grafo interactivo.
Se llama Flowsint y los analistas de ciberseguridad e investigadores ya lo están usando.
✅ Mapea relaciones entre dominios, IPs, organizaciones, wallets y perfiles sociales
✅ Enriquecimiento automatico - clic derecho en cualquier nodo y se expande solo
✅ Todo se almacena en tu máquina. Cero datos en la nube.
✅ Neo4j como base de datos de grafos. FastAPI backend. Docker en un comando.
✅ Compatible con investigaciones OSINT, due diligence y análisis de competencia
✅ v1.2.9 publicada hace 2 dias. Mantenimiento activo.
✅ 4k estrellas. 539 forks. Apache 2.0.
El mismo tipo de herramienta que usan los periodistas de investigación y analistas de inteligencia.
Gratis. En tu servidor. Sin que nadie sepa lo que estás investigando.
el enlace 👇
El web scraping acaba de cambiar de nivel
Scrapling evita los bloqueos de Cloudflare, es 774 veces más rápido que BeautifulSoup y no necesita configuración de proxies
52.2k estrellas en GitHub
No es otro scraper más
Es un framework adaptativo que aprende la estructura de cada web y se ajusta automáticamente cuando cambia
Sin mantenimiento manual. Sin que te bloqueen.
✅ Bypassa Cloudflare y los anti-bots más agresivos
✅ 774x más rápido que BeautifulSoup en benchmarks reales
✅ Sin necesidad de proxies ni configuración especial
✅ Se adapta automáticamente cuando cambia la estructura de la web
✅ Compatible con agentes de IA como servidor MCP
✅ Soporte para JavaScript, iframes y contenido dinámico
✅ Modo stealth para webs con detección avanzada
✅ 46 releases. Actualizado la semana pasada.
✅ Licencia BSD-3
Lo que antes tardabas días en montar y mantener ahora son minutos
52.2k estrellas. 5k forks. BSD-3.
repo aquí 👇
el ingeniero que construyó Claude Code acaba de publicar un video de 28 minutos sobre cómo escribir prompts que realmente funcionan
he visto cursos de 300$ que no cubren lo que él muestra en los primeros 10 minutos
archivos CLAUDE.md, atajos de memoria, sesiones paralelas, patrones de prompting
todo en un video y completamente gratis
funciona seas desarrollador, principiante o alguien que lleva meses usando Claude
a partir de esto preparé 18 cosas que puedes copiar y usar en Claude hoy mismo
guía completa en el artículo de abajo
🚨 Bir kullanıcı Yapay zekâ güvenlik filtrelerindeki güvenlik açıklarını otomatik olarak keşfedebilen
💥 Decepticon adlı bir araç açık kaynaklı hale getirildi. Bu, kırmızı ekip testlerini otomatikleştirmek için kullanılan açık kaynaklı bir çerçevedir.
🚨
Model filtrelerinizin hata noktalarını hassas bir şekilde belirlemek için gelişmiş aldatma teknikleri kullanır. %100 açık kaynaklıdır.🔥
Alguien ha creado el juego más adictivo para aprender redes de centros de datos. Esta increíblee!
Se llama Data Center; cuesta 6 dólares y empiezas con el suelo completamente vacío: compras racks, montas servidores y tiendes cada cable a mano.
Lo más brutal es que el tráfico de cada cliente se visualiza como esferas de colores que circulan por tus cables, literalmente ves los cuellos de botella en tiempo real.
190 reseñas en 48 horas, gente con equipos equipados con tarjetas RTX 4090 está totalmente enganchada y divirtiéndose en un simulador de cableado de 6 dólares.
⚠️ ATENCIÓN COMUNIDAD
#Booking confirmó que datos de reservas de usuarios fueron accedidos por terceros no autorizados.
Si tienes una reserva activa, presta atención a las notificaciones que estás recibiendo.
🚨BREAKING: You can now run Claude Code for FREE.
No API costs. No rate limits. 100% local on your machine.
Here's how to run Claude Code locally (100% free & fully private):