Raptor wafRaptor - WAF - Web application firewall using DFA [ Current version ] - Beta
AutosqliAn automatic SQL Injection tool which takes advantage of ~DorkNet~ Googler, Ddgr, WhatWaf and sqlmap.
Wafw00fWAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
SksSecurity Knowledge Structure(安全知识汇总)
WafpassAnalysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.
Docker WafAn NGINX and ModSecurity based Web Application Firewall for Docker
WhatwafDetect and bypass web application firewalls and protection systems
CuriefenseCuriefense is a unified, open source platform protecting cloud native applications.
Go AgentSqreen's Application Security Management for the Go language
TeslaTesla is a gateway service that provides dynamic routing,waf,support spring cloud,gRPC,DUBBO and more.
DotnetpadThe Waf DotNetPad is a simple and fast code editor that makes fun to program with C# or Visual Basic.
Awesome Cloud SecurityCurated list of awesome cloud security blogs, podcasts, standards, projects, and examples.
CidramCIDRAM: Classless Inter-Domain Routing Access Manager.
Vxscanpython3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。
Hoomanhttp interceptor to hoomanize cloudflare requests
Pwn SandboxA sandbox to protect your pwn challenges being pwned in CTF AWD.
IroncladWeb Application Firewall (WAF) on Kubernetes
Burpsuite CollectionsBurpSuite收集:包括不限于 Burp 文章、破解版、插件(非BApp Store)、汉化等相关教程,欢迎添砖加瓦---burpsuite-pro burpsuite-extender burpsuite cracked-version hackbar hacktools fuzzing fuzz-testing burp-plugin burp-extensions bapp-store brute-force-attacks brute-force-passwords waf sqlmap jar
XwafxWAF 3.0 - Free Web Application Firewall, Open-Source.
WafidWafid identify and fingerprint Web Application Firewall (WAF) products.
Haproxy WiWeb interface for managing Haproxy, Nginx and Keepalived servers
JanusecJanusec Application Gateway, Provides Fast and Secure Application Delivery. JANUSEC应用网关,提供快速、安全的应用交付。
JxwafJXWAF(锦衣盾)是一款开源web应用防火墙
Build TeaWeb-可视化的Web代理服务。DEMO: http://teaos.cn:7777
BlazyBlazy is a modern login bruteforcer which also tests for CSRF, Clickjacking, Cloudflare and WAF .
OpenwafWeb security protection system based on openresty
Waf🚦Web Application Firewall or API Gateway(应用防火墙/API网关)
WafWin Application Framework (WAF) is a lightweight Framework that helps you to create well structured XAML Applications.
BurpsuitehttpsmugglerA Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques
AwsA collection of bash shell scripts for automating various tasks with Amazon Web Services using the AWS CLI and jq.
ModsecurityModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analys…
Awesome Nginx Security🔥 A curated list of awesome links related to application security related to the environments with NGINX or Kubernetes Ingres Controller (based on NGINX)
Cerberus一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
NaxsiNAXSI is an open-source, high performance, low rules maintenance WAF for NGINX
Awesome Waf🔥 Everything about web-application firewalls (WAF).
Xash3d FwgsXash3D FWGS engine. Rebooted fork since big Xash3D 0.99(1.0 is not yet) update.
Htrace.shMy simple Swiss Army knife for http/https troubleshooting and profiling.
JugglerA system that may trick hackers. 一个也许能骗到黑客的系统。
CloudbunnyCloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to search domain information: Shodan, Censys and Zoomeye.
Fomalhaut🚀 A Simple API Gateway for Building Security and Flexible Microservices.
broomA disk cleaning utility for developers.
litewafLightweight In-App Web Application Firewall for PHP
k8s-lempLEMP stack in a Kubernetes cluster
ftwFramework for Testing WAFs (FTW!)