
ftw
YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

The most powerful CRLF injection (HTTP Response Splitting) scanner.

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

A fast, simple, recursive content discovery tool written in Rust.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

WebPwn3r - Web Applications Security Scanner.


This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

Multi-mode vulnerability scanner for Next.js RCE (CVE-2025-66478/55182) with safe side-channel detection, RCE proof-of-concept, WAF bypass…

Log4j-RCE (CVE-2021-44228) Proof of Concept