
cloudbunny
CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

Tool to bypass 40X response codes.

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

IP obfuscator made to make a malicious ip a bit cuter

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

Disrupt WAF by abusing SSL/TLS Ciphers

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.


Detect and bypass web application firewalls and protection systems

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…