Ekultek / WhatWaf
Detect and bypass web application firewalls and protection systems
☆2,756Updated 8 months ago
Alternatives and similar repositories for WhatWaf:
Users that are interested in WhatWaf are comparing it to the libraries listed below
- File upload vulnerability scanner and exploitation tool.☆3,190Updated 2 years ago
- WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.☆5,598Updated 3 months ago
- A Tool for Domain Flyovers☆5,747Updated 2 years ago
- Automated NoSQL database enumeration and web application exploitation tool.☆3,047Updated 8 months ago
- Knock Subdomain Scan☆3,967Updated 5 months ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆3,919Updated last year
- Next generation web scanner☆5,822Updated 9 months ago
- 🔥 Web-application firewalls (WAFs) from security standpoint.☆6,604Updated 5 months ago
- A curated list of amazingly awesome Burp Extensions☆3,143Updated 2 months ago
- A Workflow Engine for Offensive Security☆5,558Updated 2 months ago
- HTTP parameter discovery suite.☆5,568Updated 2 months ago
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,258Updated 5 months ago
- Striker is an offensive information and vulnerability scanner.☆2,269Updated last year
- Advanced vulnerability scanning with Nmap NSE☆3,596Updated 7 months ago
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and…☆3,779Updated 3 years ago
- Bruteforcing from various scanner output - Automatically attempts default creds on found services.☆2,230Updated this week
- Automatic SSRF fuzzer and exploitation tool☆3,159Updated last month
- A high performance offensive security tool for reconnaissance and vulnerability scanning☆3,163Updated 10 months ago
- Find web directories without bruteforce☆1,826Updated last year
- A python script that finds endpoints in JavaScript files☆3,901Updated last year
- The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, su…☆3,437Updated last year
- Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run yo…☆3,675Updated last week
- Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application☆4,645Updated 4 months ago
- Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.☆4,306Updated 3 months ago
- CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs☆2,406Updated last year
- Automated All-in-One OS Command Injection Exploitation Tool.☆5,243Updated last week
- Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.☆3,693Updated 2 months ago
- NSE script based on Vulners.com API☆3,296Updated last year
- Web application fuzzer☆6,148Updated 8 months ago
- Subdomain Takeover tool written in Go☆1,959Updated last year