
Dorkwright
From Dork to Download: Automating Google Dorks with Playwright

From Dork to Download: Automating Google Dorks with Playwright

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

A SOCKS proxy written in Python that randomizes your source IP address. Round-robin your evil packets through SSH tunnels or give them billions of…


teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Blind WAF identification tool

Automated web security auditing tool that detects environment misconfigurations, probes backend vulnerabilities, and bypasses WAF/IDS protections…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.


Disrupt WAF by abusing SSL/TLS Ciphers

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Next generation web scanner

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…