
coraza
Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

CVE-2025-55182 (React2Shell) Scanner

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Professional-grade Denial of Service (DoS) exploitation framework for CVE-2025-55184 targeting React Server Components. Features 8 attack modes, WAF…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

A cheat sheet that contains advanced queries for SQL Injection of all types.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Tests your WAF with +160 payloads

MISP <= 2.5.27 - Stored Cross-Site Scripting via Workflow Engine (doT.js Template Injection).

A new way to exploit CVE-2025-58360 bypass WAF

Testing WAF protection against CVE-2021-44228 Log4Shell

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

A guided mutation-based fuzzer for ML-based Web Application Firewalls

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…