
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Automates HTTP 403 access control bypass techniques using header manipulation, path obfuscation, and HTTP method conversion for web application…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Tests your WAF with +160 payloads

Tools for auditing WAFS

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

A guided mutation-based fuzzer for ML-based Web Application Firewalls

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.