
coreruleset
Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

A simple script just made for self use for bypassing 403

My simple Swiss Army knife for http/https troubleshooting and profiling.

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

HackBar plugin for Burpsuite

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

Automates HTTP 403 access control bypass techniques using header manipulation, path obfuscation, and HTTP method conversion for web application…

Tools for auditing WAFS