
TLS-Attacker
Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

The Offensive Manual Web Application Penetration Testing Framework.

Automatic SSTI detection tool with interactive interface

A wordlist of API names for web application assessments

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

Tools for auditing WAFS

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.

Go Web Application Penetration Test

Software for fuzzing, used on web application pentestings.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

A structure-aware JSON fuzzer


CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

Command Injection Web Fuzzer Script for mitmproxy

Simple python script to fuzz site for CVE-2017-9805