


Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Tools for auditing WAFS

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Burp Plugin to Bypass WAFs through the insertion of Junk Data

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Like curl, but it gets past Anubis and Cloudflare bot-walls.

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

Stop getting 403 Forbidden. A specialized httpx-like toolkit for WAF evasion.