
sqlmap
Automatic SQL injection and database takeover tool

Automatic SQL injection and database takeover tool

Local file inclusion exploitation tool

Automated All-in-One OS Command Injection Exploitation Tool

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Disrupt WAF by abusing SSL/TLS Ciphers

Blind WAF identification tool

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

A fast, simple, recursive content discovery tool written in Rust.

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Reverse Engineer of Trust Decision Chinese Security

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!