mmarting / unwafView external linksLinks
Unwaf is a Go tool designed to help identify WAF bypasses using passive techniques, such as: SPF records and DNS history. By default, Unwaf will check SPF records.
☆98Jul 4, 2025Updated 7 months ago
Alternatives and similar repositories for unwaf
Users that are interested in unwaf are comparing it to the libraries listed below
Sorting:
- Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration☆12Jun 2, 2024Updated last year
- NetScan CLI is a command-line tool for retrieving and analyzing IP address information. It provides detailed subnet and organization data…☆62Sep 4, 2024Updated last year
- JScripter is a Python script designed to scrape and save unique JavaScript files from a list of URLs or a single URL.☆29Nov 26, 2024Updated last year
- SubOwner - A Simple tool check for subdomain takeovers.☆116Oct 18, 2024Updated last year
- SNMP Bash Script to discover valid community strings, dump basic information, check for write permission and check for RCE.☆11Apr 27, 2024Updated last year
- Powershell Scripts for Blue Team members☆11Dec 1, 2023Updated 2 years ago
- A powerful asynchronous XSS scanner supporting up to 1,500 concurrent requests.☆164Aug 16, 2024Updated last year
- PrestaXSRF is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆31Dec 26, 2023Updated 2 years ago
- CVE-2023-6063 (WP Fastest Cache < 1.2.2 - UnAuth SQL Injection)☆29Nov 15, 2023Updated 2 years ago
- Will attempt to retrieve DB details for FastAdmin instances☆69Aug 20, 2024Updated last year
- ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities. It crawls a target website, extracts GET…☆63Feb 22, 2025Updated 11 months ago
- A simple bug bounty utility tool to remove uninteresting entries from a list of URLs.☆14Jul 22, 2024Updated last year
- aiohttp LFI (CVE-2024-23334)☆27Mar 19, 2024Updated last year
- Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.☆24Feb 20, 2024Updated last year
- Tool to parse subdomains from dmarc.live☆149Apr 19, 2024Updated last year
- SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty☆725Jan 25, 2026Updated 2 weeks ago
- Scrape domain names from SSL certificates of arbitrary hosts☆689Mar 31, 2024Updated last year
- POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.☆125Jul 12, 2024Updated last year
- Bug bounty domain manager with validation, exports & Redis storage ✨☆29Jun 5, 2025Updated 8 months ago
- CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow☆26Jul 13, 2024Updated last year
- A modern tool written in Python that automates your xss findings.☆470Nov 26, 2023Updated 2 years ago
- ☆128Jul 15, 2021Updated 4 years ago
- Unauthorized Access to Metadata and User Data like CTF☆28Nov 30, 2024Updated last year
- ☆47Jan 14, 2024Updated 2 years ago
- A proof of concept program that pulls and parses security.txt files at mass.☆28May 31, 2023Updated 2 years ago
- Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution☆80Feb 6, 2024Updated 2 years ago
- 🚀 XSSFUZZ - A tool for detecting XSS vulnerabilities in web applications.☆123Sep 13, 2024Updated last year
- Web Penetration Testing Course Materials☆32May 13, 2024Updated last year
- Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp…☆29Jul 21, 2024Updated last year
- ☆173Aug 9, 2025Updated 6 months ago
- Parse FFUF results in GUI with option to sort based by response code , size , keyword☆100Sep 9, 2024Updated last year
- Subdomains wordlist generted from subdomains of public bug bounty programs☆11Mar 25, 2025Updated 10 months ago
- Scan websites CSP policies and visualise their vunlnerabilities from a dashboard☆13Mar 11, 2025Updated 11 months ago
- Android webviews and securiy☆23Sep 18, 2025Updated 4 months ago
- this repo contains all nuclei templates for particular vulnerability that i used mosty while hunting..☆10Aug 15, 2024Updated last year
- 蜜罐检测工具,支持自动化URL去重、多线程控制及智能速率限制。可识别伪装服务。☆16Jun 5, 2025Updated 8 months ago
- Exploit for CVE-2024-3273, supports single and multiple hosts☆13Apr 7, 2024Updated last year
- This is a python wrapper around the amazing KNOXSS API by Brute Logic☆279Jan 12, 2026Updated last month
- The tool that bypasses the firewall's Application Based Rules and lets you connect to anywhere, ANY IP, ANY PORT and ANY APPLICATION.☆61Aug 19, 2024Updated last year