
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…


Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automatic SQL injection and database takeover tool

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

Automated All-in-One OS Command Injection Exploitation Tool

Tools for auditing WAFS

Blind WAF identification tool

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

A fast, simple, recursive content discovery tool written in Rust.

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Reverse Engineer of Trust Decision Chinese Security

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…