
ftw
YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Collection of quality safety articles. Awesome articles.

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…


Runtime application self-protection engine that hooks into application servers to monitor and block malicious database queries, file operations, and…

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

CVE-2021-44228 log4j mitigation using aws wafv2 with ansible