
WAF-A-MoLE
A guided mutation-based fuzzer for ML-based Web Application Firewalls

A guided mutation-based fuzzer for ML-based Web Application Firewalls

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)



A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…


pentest on MagnoHost hosting provider & MeteorCloud infrastructure with 15+ servers mapped. Findings: MariaDB exposed on 6 servers, OmniDialer…

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

My simple Swiss Army knife for http/https troubleshooting and profiling.

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

First iteration of ML based Feedback WAF

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全…