
Cuteit
IP obfuscator made to make a malicious ip a bit cuter

IP obfuscator made to make a malicious ip a bit cuter

Detect and bypass web application firewalls and protection systems

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

Tool to bypass 40X response codes.

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

Disrupt WAF by abusing SSL/TLS Ciphers

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.


WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

Automated web security auditing tool that detects environment misconfigurations, probes backend vulnerabilities, and bypasses WAF/IDS protections…

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)