


Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Detect and bypass web application firewalls and protection systems

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…


A cheat sheet that contains advanced queries for SQL Injection of all types.

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Advanced reconnaissance utility

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.

Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)

Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration,…

Advanced SQL Injection Scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications…

Burp Suite extension for automated detection and exploitation of HTTP request smuggling vulnerabilities, supporting HTTP/1.1 and HTTP/2-downgrade…

Local file inclusion exploitation tool

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.