
WhatWeb
Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Web application firewall testing tool with 344+ attack payloads, auto WAF detection, bypass techniques, and full reconnaissance including DNS,…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

High-performance web fuzzer for content discovery, virtual host enumeration, and parameter fuzzing. Supports recursive scanning, multi-wordlist…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Advanced web path brute-forcer for discovering hidden directories and files. Supports recursive scanning, custom wordlists, filters, proxies, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

High-performance Rust HTTP/HTTPS proxy with active defense: rate limiting, reputation-based access, WAF (anti-bot, anti-injection, path protection),…

A fast, simple, recursive content discovery tool written in Rust.

Automatic SQL injection and database takeover tool

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Enterprise WAF evaluation tool that sends 90 real attack payloads across 6 suites (OWASP, API, bypass, rate limiting) and generates compliance-ready…