


Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

HTTP Request Smuggling over HTTP/2 Cleartext (h2c)

Curated XSS payload collection and filter-bypass cheat sheet: WAF-specific evasion, JS/HTML injection vectors, encoding tricks, DOMPurify and…


Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.


Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Collection of tools to use with Azure Applications

Open-source cross-modal and multimodal prompt injection test suite. 250,000+ attack payloads across text, image, document, and audio modalities.…

A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

This repo exists as a quick and dirty arsenal of methods and scripts to subvert .NET SSL/TLS certificate validation in PowerShell and press on with…


USBCoercer turns an ESP32 development board with native USB-OTG into an Ethernet-over-USB gadget capable of coercing proxy configuration via WPAD.

Prevent CVE-2025-22457 and other security problems with Juniper/Ivanti Secure Connect SSL VPN