
ftw
YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

Next-gen logical WAF engine built in SWI-Prolog. Features an inductive learning brain running at 2M+ LIPS with an integrated recursive decoder to…

Testing WAF protection against CVE-2021-44228 Log4Shell

CVE-2025-55182 (React2Shell) Scanner

Professional-grade Denial of Service (DoS) exploitation framework for CVE-2025-55184 targeting React Server Components. Features 8 attack modes, WAF…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

A cheat sheet that contains advanced queries for SQL Injection of all types.

Tests your WAF with +160 payloads

A guided mutation-based fuzzer for ML-based Web Application Firewalls

MISP <= 2.5.27 - Stored Cross-Site Scripting via Workflow Engine (doT.js Template Injection).

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.