


Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Precision-Based Detection of RSC/Next.js Remote Code Execution Vulnerabilities (CVE-2025-55182, CVE-2025-66478)

This is the data that powers the PortSwigger URL validation bypass cheat sheet.

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…


Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…

Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

Burp Plugin to Bypass WAFs through the insertion of Junk Data


This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.


The most powerful CRLF injection (HTTP Response Splitting) scanner.

A cheat sheet that contains advanced queries for SQL Injection of all types.
