
lua-resty-waf
High-performance WAF built on the OpenResty stack

High-performance WAF built on the OpenResty stack

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

Local privacy proxy that replaces secrets and PII before AI requests leave your machine.

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

Nuclei template for CVE-2026-41473 - CyberPanel AI Scanner unauthenticated read/write API access (< 2.4.4)

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Burp Suite Extension useful to verify OAUTHv2 and OpenID security


FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

A coverage-guided REST API fuzzer developed on top of LibAFL

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…


Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.


Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…