
evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).
EvilWAF is an advanced transparent MITM Firewall bypass proxy and deep WAF vulnerability scanner designed for authorized security testing. It operates at the transport layer — it does not touch payloads, cookies, or headers from your tools. Works with any tool like(ffuz, sqlmap, nuclei and etc) that supports --proxy.
--proxy. Zero configuration on tool side.CF-Connecting-IP, CF-Ray, True-Client-IP) with crafted values to test WAF header trust and attempt IP allowlist bypass.Layer 1 Network — Virtual host bypass, sensitive path probing, Host header manipulationLayer 2 RuleEngine — Payload-based rule-gap detection: SQLi, XSS, RCE, LFILayer 3 RateLimit — Burst and sustained rate-limit enforcement testingLayer 4 Evasion — Encoding and normalisation bypass with 10 encoding variants per payloadLayer 5 Behavioural — Timing analysis: tarpit, JS challenge delay, back-off detectionLayer 6 Header — HTTP header injection and IP spoofing bypassLayer 7 TLS — TLS version probing, SNI bypass, certificate fingerprintingLayer 8 MethodVerb — HTTP method bypass including WebDAV methodsLayer 9 Session — Cookie manipulation, auth bypass, session fixation probesLayer 10 Misconfig — WAF misconfiguration and information leak detection_fast_scanner.c) — High-performance Python C extension for classification, entropy analysis, timing anomaly detection, and statistics hot paths.--no-tui flag for scripting and CI/CD pipelines.--scan-only to run the WAF vulnerability scanner standalone without starting the proxy.Cloudflare is widely regarded as the most sophisticated Web Application Firewall in the world today. It is not simply a set of rules — it is a multi-layered defence system that combines several technologies working simultaneously to protect web applications.
At the network level, Cloudflare operates across hundreds of data centres globally, meaning every request passes through infrastructure that has visibility into traffic patterns from millions of websites at once. This global visibility is one of its most powerful advantages — it can detect attack patterns emerging anywhere in the world and deploy mitigations across all protected properties within seconds.
At the inspection level, Cloudflare analyses requests across multiple dimensions simultaneously: TCP/IP fingerprint, TLS fingerprint, HTTP/2 frame structure, header ordering, request timing, behavioural patterns across sessions, and payload content. Any single one of these signals alone is not enough to block a request, but Cloudflare correlates all of them together to build a risk score per request.
The machine learning component is what makes Cloudflare fundamentally different from traditional WAFs. Where rule-based WAFs look for known bad patterns, Cloudflare's ML models are trained on petabytes of real attack traffic. They learn what legitimate browser traffic looks like at the transport layer — the exact sequence of TCP options, the precise structure of a TLS ClientHello, the ordering of HTTP/2 SETTINGS frames — and flag anything that deviates from that baseline, even if the payload itself appears clean. This is why simply encoding a payload or rotating headers is not enough against Cloudflare. The bypass has to happen at the transport layer, not the application layer.
Most WAF bypass techniques target the rule engine — obfuscating payloads, using encoding variants, splitting attack strings across parameters. These techniques work against signature-based WAFs because those WAFs only look at payload content.
Cloudflare's defence operates before the payload is even inspected. A request from a Python HTTP library, even sending a completely benign payload, can be challenged or blocked because the TLS fingerprint does not match any known browser. This means the tool making the request is identified before the content is analysed. Cloudflare calls this behavioural fingerprinting, and it is the primary reason standard penetration testing tools fail against it even when the underlying payloads are correct.
Rate limiting on Cloudflare is also intelligent — it is not simply a counter of requests per IP per second. It tracks request patterns across sessions, correlates behaviour across IPs sharing the same ASN, and applies progressive challenges rather than hard blocks, making it difficult to detect the threshold through automated testing.