
awswaf
AWS WAF Solver, full reverse implemented in 100% Python & Golang.

AWS WAF Solver, full reverse implemented in 100% Python & Golang.


40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

react2shell PoC with Go / CVE-2025-55182

Like curl, but it gets past Anubis and Cloudflare bot-walls.

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

High-performance Go implementation for detecting React Server Components RCE vulnerabilities (CVE-2025-55182 & CVE-2025-66478).

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Tools for auditing WAFS

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

New nuclei CVE