
waf-checker
Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A fast, simple, recursive content discovery tool written in Rust.

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB


Executable security regression testing for agentic applications and MCP-integrated systems.

Burp extension for wordpress security scanning

REST/JSON API to the Burp Suite security tool.

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR