WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
☆6,237Jan 27, 2026Updated last month
Alternatives and similar repositories for wafw00f
Users that are interested in wafw00f are comparing it to the libraries listed below
Sorting:
- Web path scanner☆14,084Updated this week
- OneForAll是一款功能强大的子域收集工具☆9,677Sep 12, 2025Updated 6 months ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,812Dec 4, 2025Updated 3 months ago
- Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥☆7,398Aug 28, 2025Updated 6 months ago
- JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.☆2,920Nov 24, 2021Updated 4 years ago
- Detect and bypass web application firewalls and protection systems☆2,875Aug 11, 2024Updated last year
- Next generation web scanner☆6,461Oct 19, 2025Updated 5 months ago
- Fast subdomains enumeration tool for penetration testers☆10,855Aug 2, 2024Updated last year
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆27,492Updated this week
- Fast web fuzzer written in Go☆15,750Apr 24, 2025Updated 10 months ago
- HTTP parameter discovery suite.☆6,142Feb 20, 2025Updated last year
- “冰蝎”动态二进制加密网站管理客户端☆6,143Aug 24, 2023Updated 2 years ago
- A python script that finds endpoints in JavaScript files☆4,300Apr 13, 2024Updated last year
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,125Apr 21, 2024Updated last year
- Most advanced XSS scanner.☆14,822Apr 26, 2025Updated 10 months ago
- Web application fuzzer☆6,445Jan 21, 2026Updated 2 months ago
- You Know, For WEB Fuzzing !☆8,273Nov 13, 2023Updated 2 years ago
- 一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档☆11,471Oct 29, 2024Updated last year
- Fast passive subdomain enumeration tool.☆13,283Updated this week
- A fast vulnerability scanner helps pentesters pinpoint possibly vulnerable targets from a large number of web servers☆2,369Dec 31, 2024Updated last year
- This is a webshell open source project☆10,701Dec 24, 2024Updated last year
- Automatic SSRF fuzzer and exploitation tool☆3,505Sep 4, 2025Updated 6 months ago
- EHole(棱洞)3.0 重构版-红队重点攻击系统指纹探测工具☆3,445Apr 2, 2024Updated last year
- A Tool for Domain Flyovers☆5,912May 22, 2022Updated 3 years ago
- A fast sub domain brute tool for pentesters☆3,607Sep 15, 2022Updated 3 years ago
- httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.☆9,695Updated this week
- Pre-Built Vulnerable Environments Based on Docker-Compose☆20,399Updated this week
- A `.git` folder disclosure exploit☆3,526Feb 1, 2023Updated 3 years ago
- pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.☆3,829Feb 28, 2025Updated last year
- Impacket is a collection of Python classes for working with network protocols.☆15,560Updated this week
- Burp suite 分块传输辅助插件☆2,026Feb 23, 2022Updated 4 years ago
- A swiss army knife for pentesting networks☆9,100Dec 6, 2023Updated 2 years ago
- 哥斯拉☆4,345Jul 17, 2024Updated last year
- windows-kernel-exploits Windows平台提权漏洞集合☆8,617Jun 11, 2021Updated 4 years ago
- A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for att…☆5,820Updated this week
- Linux privilege escalation auditing tool☆6,420Feb 19, 2026Updated last month
- In-depth attack surface mapping and asset discovery☆14,282Updated this week
- Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack…☆3,213May 24, 2024Updated last year
- 一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN…☆3,515Dec 18, 2022Updated 3 years ago