
web-hacking-playground
Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

A guided mutation-based fuzzer for ML-based Web Application Firewalls

Collaborative application security testing between humans and agents via CLI and MCP

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Application Security Verification Standard

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

The Swiss Army knife for automated Web Application Testing

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

TCP tunneling over HTTP/HTTPS for web application servers

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

A wordlist of API names for web application assessments

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.