Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
evilwaf — evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs). | Kitploit
Tools/GitHubGitHub/matrixleons/evilwaf
OSINT (Open Source Intelligence)Vulnerability ScannersWeb Proxies & InterceptionInformation GatheringWAF BypassPenetration TestingSubdomain EnumerationRed TeamingFingerprint Spoofing
GitHubmatrixleons/evilwaf

evilwaf

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

883103371 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

Stars License Python Platform


EvilWAF is an advanced transparent MITM Firewall bypass proxy and deep WAF vulnerability scanner designed for authorized security testing. It operates at the transport layer — it does not touch payloads, cookies, or headers from your tools. Works with any tool like(ffuz, sqlmap, nuclei and etc) that supports --proxy.


Features

Proxy & Bypass

  • Transparent MITM Proxy — Works with any tool that supports --proxy. Zero configuration on tool side.
  • TCP Fingerprint Rotation — Rotates TCP stack options per request to avoid behavioral detection.
  • TLS Fingerprint Rotation — Rotates TLS fingerprint (JA3/JA4 style) paired with TCP profiles.
  • HTTP/2 Fingerprint Rotation — Per-request H2 SETTINGS and HEADERS frame profile rotation cycling through Chrome, Firefox, Safari, and Edge profiles to prevent WAF behavioral fingerprinting.
  • Source Port Manipulation — Rotates source port per request, breaking WAF session tracking and rate-limit counters that rely on source port consistency.
  • Cloudflare Header Injection — Injects Cloudflare-specific internal headers (CF-Connecting-IP, CF-Ray, True-Client-IP) with crafted values to test WAF header trust and attempt IP allowlist bypass.
  • Tor IP Rotation — Routes traffic through Tor and rotates exit IP every request automatically.
  • Proxy Pool IP Rotation — Rotates IP every request through external proxy pool.
  • Origin IP Hunter — Discovers the real server IP behind the WAF using 10 parallel scanners:
    • DNS history, SSL certificate analysis, subdomain enumeration
    • DNS misconfiguration, cloud leak detection, GitHub leak search
    • HTTP header leak, favicon hash, ASN range scan, Censys
  • Auto WAF Detection — Detects WAF vendor automatically before bypass starts.
  • Direct Origin Bypass — Once real IP is found, routes all traffic directly to the server, skipping the WAF entirely.
  • Full HTTPS MITM — Intercepts and inspects HTTPS traffic with dynamic certificate generation per host.
  • HTTP/2 & HTTP/1.1 Support — Negotiates ALPN automatically and handles both protocols.
  • Response Advisor — Automatically retries on WAF blocks (403, 429, 503) with different techniques.

WAF Vulnerability Scanner

  • Deep Multi-Layer WAF Scanner — Treats the firewall itself as the target. Analyses all WAF defensive layers simultaneously across 10 independent scanning layers:
    • Layer 1 Network — Virtual host bypass, sensitive path probing, Host header manipulation
    • Layer 2 RuleEngine — Payload-based rule-gap detection: SQLi, XSS, RCE, LFI
    • Layer 3 RateLimit — Burst and sustained rate-limit enforcement testing
    • Layer 4 Evasion — Encoding and normalisation bypass with 10 encoding variants per payload
    • Layer 5 Behavioural — Timing analysis: tarpit, JS challenge delay, back-off detection
    • Layer 6 Header — HTTP header injection and IP spoofing bypass
    • Layer 7 TLS — TLS version probing, SNI bypass, certificate fingerprinting
    • Layer 8 MethodVerb — HTTP method bypass including WebDAV methods
    • Layer 9 Session — Cookie manipulation, auth bypass, session fixation probes
    • Layer 10 Misconfig — WAF misconfiguration and information leak detection
  • Persistent Session — Each scan merges with historical JSON data from previous scans. Confidence grows over time — the longer you scan, the more accurate the results.
  • Statistical Confidence Engine — Per-layer confidence scores computed using mean, standard deviation, and stability analysis. A finding at 86% confidence after 15 verified passes is a real vulnerability, not noise.
  • False Positive Verification — Every finding is replayed against a clean baseline before reporting. Findings that do not reproduce are automatically excluded.
  • C Extension (_fast_scanner.c) — High-performance Python C extension for classification, entropy analysis, timing anomaly detection, and statistics hot paths.

Interface

  • TUI Dashboard — Real-time terminal UI showing live traffic, active techniques, Tor IPs, source ports, proxy pool, and scanner findings per layer.
  • Headless Mode — --no-tui flag for scripting and CI/CD pipelines.
  • Scan-Only Mode — --scan-only to run the WAF vulnerability scanner standalone without starting the proxy.

About Cloudflare & Research

Why Cloudflare?

Cloudflare is widely regarded as the most sophisticated Web Application Firewall in the world today. It is not simply a set of rules — it is a multi-layered defence system that combines several technologies working simultaneously to protect web applications.

At the network level, Cloudflare operates across hundreds of data centres globally, meaning every request passes through infrastructure that has visibility into traffic patterns from millions of websites at once. This global visibility is one of its most powerful advantages — it can detect attack patterns emerging anywhere in the world and deploy mitigations across all protected properties within seconds.

At the inspection level, Cloudflare analyses requests across multiple dimensions simultaneously: TCP/IP fingerprint, TLS fingerprint, HTTP/2 frame structure, header ordering, request timing, behavioural patterns across sessions, and payload content. Any single one of these signals alone is not enough to block a request, but Cloudflare correlates all of them together to build a risk score per request.

The machine learning component is what makes Cloudflare fundamentally different from traditional WAFs. Where rule-based WAFs look for known bad patterns, Cloudflare's ML models are trained on petabytes of real attack traffic. They learn what legitimate browser traffic looks like at the transport layer — the exact sequence of TCP options, the precise structure of a TLS ClientHello, the ordering of HTTP/2 SETTINGS frames — and flag anything that deviates from that baseline, even if the payload itself appears clean. This is why simply encoding a payload or rotating headers is not enough against Cloudflare. The bypass has to happen at the transport layer, not the application layer.

Why Is Cloudflare Hard to Bypass?

Most WAF bypass techniques target the rule engine — obfuscating payloads, using encoding variants, splitting attack strings across parameters. These techniques work against signature-based WAFs because those WAFs only look at payload content.

Cloudflare's defence operates before the payload is even inspected. A request from a Python HTTP library, even sending a completely benign payload, can be challenged or blocked because the TLS fingerprint does not match any known browser. This means the tool making the request is identified before the content is analysed. Cloudflare calls this behavioural fingerprinting, and it is the primary reason standard penetration testing tools fail against it even when the underlying payloads are correct.

Rate limiting on Cloudflare is also intelligent — it is not simply a counter of requests per IP per second. It tracks request patterns across sessions, correlates behaviour across IPs sharing the same ASN, and applies progressive challenges rather than hard blocks, making it difficult to detect the threshold through automated testing.

The Developer's Research Approach

Download Tool