
sqlmap
Automatic SQL injection and database takeover tool

Automatic SQL injection and database takeover tool

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Automated Αll-in-One OS command injection exploitation tool.

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Python PoC and scanner for CVE-2026-87902, a WordPress core path traversal leading to LFI and PEAR-based RCE, with WAF bypass and automated…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Blind WAF identification tool

Like curl, but it gets past Anubis and Cloudflare bot-walls.

A fast, simple, recursive content discovery tool written in Rust.

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…