
impersonate-proxy
A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Burp Plugin to Bypass WAFs through the insertion of Junk Data

This script automates SQL injection testing using SQLMap with AI-powered decision making.

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

A cheat sheet that contains advanced queries for SQL Injection of all types.

woodpecker-plugins

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques


burp伪造ip爆破脚本