
bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Cloud-based Web Application Firewall (WAF) providing L3/L7 protection against SQLi, XSS, DDoS, and bot attacks. Features AI assistant, anti-bot…

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

Exploit for CVE-2023-33246 targeting Apache RocketMQ 5.1.0, enabling remote code execution via crafted packet injection into the broker's update…

Application scanning component of purpleteam

Stage two containers

Orchestration component of purpleteam

TLS checking component of purpleteam

Server scanning component of purpleteam

CLI component of purpleteam

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

Permission Manager is a project that brings sanity to Kubernetes RBAC and Users management, Web UI FTW

An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

Open Source Cloud Native Application Protection Platform (CNAPP)

Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

Multi-cloud security posture scanner that audits AWS, Azure, GCP, and OCI for misconfigurations, compliance violations (HIPAA, PCI, CIS), and…

Monitoring centralisé pour instances Nextcloud multiples