
crowdsec
Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Undetected version of the Playwright testing and automation library.

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

↕️🤫 Stealth redirector for your red team operation security

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

Stop getting 403 Forbidden. A specialized httpx-like toolkit for WAF evasion.

Header bypass for CVE-2025-55182 (React Server Components RCE).

CVE-2025-55182-POC

Let's help websites stay safe until they are properly patched!

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload