#1Tools for finding and exploiting weaknesses in Web Application Firewalls to bypass their protections.
Kitploit recommended

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
Automatic SQL injection and database takeover tool

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

Fast web fuzzer written in Go

Web path scanner

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Custom Selenium Chromedriver | Zero-Config | Passes ALL bot mitigation systems (like Distil / Imperva/ Datadadome / CloudFlare IUAM)

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Most advanced XSS scanner.

A fast, simple, recursive content discovery tool written in Rust.

Automated exploitation of command injection vulnerabilities. From detection to full control of the underlying operating system.