
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automated Αll-in-One OS command injection exploitation tool.

Automatic SQL injection and database takeover tool

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Local file inclusion exploitation tool

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

The most powerful CRLF injection (HTTP Response Splitting) scanner.

Disrupt WAF by abusing SSL/TLS Ciphers

Tools for auditing WAFS

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

A fast, simple, recursive content discovery tool written in Rust.

Next.js CVE-2025-29927 Vulnerability Scanner

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…