
WAF-A-MoLE
A guided mutation-based fuzzer for ML-based Web Application Firewalls

A guided mutation-based fuzzer for ML-based Web Application Firewalls

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Detect and bypass web application firewalls and protection systems

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

Automates HTTP 403 access control bypass techniques using header manipulation, path obfuscation, and HTTP method conversion for web application…

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Cloud-based Web Application Firewall (WAF) providing L3/L7 protection against SQLi, XSS, DDoS, and bot attacks. Features AI assistant, anti-bot…

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…