
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Next-gen logical WAF engine built in SWI-Prolog. Features an inductive learning brain running at 2M+ LIPS with an integrated recursive decoder to…

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

MISP <= 2.5.27 - Stored Cross-Site Scripting via Workflow Engine (doT.js Template Injection).

Tests your WAF with +160 payloads

CVE-2025-55182 (React2Shell) Scanner

A new way to exploit CVE-2025-58360 bypass WAF

Professional-grade Denial of Service (DoS) exploitation framework for CVE-2025-55184 targeting React Server Components. Features 8 attack modes, WAF…

A guided mutation-based fuzzer for ML-based Web Application Firewalls

A cheat sheet that contains advanced queries for SQL Injection of all types.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Testing WAF protection against CVE-2021-44228 Log4Shell