
BounceBack
↕️🤫 Stealth redirector for your red team operation security

↕️🤫 Stealth redirector for your red team operation security

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques


Let's help websites stay safe until they are properly patched!

Blind WAF identification tool

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

Enhance your malware detection with WAF + YARA (WAFARAY)

First iteration of ML based Feedback WAF

🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Encoder to bypass WAF filters using XOR operations.

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

A program for testing WAF functionality

A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads

Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab