


Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…

A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

React/Next.js React4Shell RCE CVE-2025-55182 checker

a simple react2shell poc with basic waf bypass

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

Local file inclusion exploitation tool

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

↕️🤫 Stealth redirector for your red team operation security