
pipelock
Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

A collection of awesome penetration testing resources, tools and other shiny things

Like Envoy xDS, but for eBPF filters

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

Pingtunnel is a tool that send TCP/UDP traffic over ICMP

CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.

A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

Tests your WAF with +160 payloads

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

AI coding agents that can't exfiltrate secrets or merge their own PRs.

Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in…

Serverless AITM Simulation Framework for Entra ID and M365