
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…


An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Like curl, but it gets past Anubis and Cloudflare bot-walls.

High-performance Go implementation for detecting React Server Components RCE vulnerabilities (CVE-2025-55182 & CVE-2025-66478).

react2shell PoC with Go / CVE-2025-55182

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

New nuclei CVE

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Tools for auditing WAFS