Unwaf is a Go tool designed to help identify WAF bypasses using passive techniques. It automates the process of discovering the real origin IP behind a WAF/CDN by combining multiple discovery methods and verifying candidates through HTML similarity comparison, SSL certificate fingerprinting, and HTTP header analysis.
☆180Feb 22, 2026Updated 3 months ago
Alternatives and similar repositories for unwaf
Users that are interested in unwaf are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- NetScan CLI is a command-line tool for retrieving and analyzing IP address information. It provides detailed subnet and organization data…☆62Sep 4, 2024Updated last year
- JScripter is a Python script designed to scrape and save unique JavaScript files from a list of URLs or a single URL.☆29Nov 26, 2024Updated last year
- Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration☆12Jun 2, 2024Updated 2 years ago
- A simple bug bounty utility tool to remove uninteresting entries from a list of URLs.☆13Jul 22, 2024Updated last year
- Firebase_Checker is Python tool to analyze APK files and web applications for Firebase-related vulnerabilities. This tool identifies secu…☆57Nov 6, 2025Updated 7 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Scrape domain names from SSL certificates of arbitrary hosts☆691Mar 31, 2024Updated 2 years ago
- Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.☆27Feb 20, 2024Updated 2 years ago
- Will attempt to retrieve DB details for FastAdmin instances☆69Aug 20, 2024Updated last year
- SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty☆777May 30, 2026Updated 2 weeks ago
- AI-powered ffuf wrapper☆783Dec 4, 2025Updated 6 months ago
- SubOwner - A Simple tool check for subdomain takeovers.☆118Oct 18, 2024Updated last year
- 🚀 XSSFUZZ - A tool for detecting XSS vulnerabilities in web applications.☆126Sep 13, 2024Updated last year
- MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.☆300Oct 5, 2024Updated last year
- A powerful asynchronous XSS scanner supporting up to 1,500 concurrent requests.☆172Aug 16, 2024Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- PrestaXSRF is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆32Dec 26, 2023Updated 2 years ago
- Custom Trickest Workflows☆12Oct 26, 2023Updated 2 years ago
- how to look for Leaked Credentials !☆1,050May 6, 2024Updated 2 years ago
- ☆132Jul 15, 2021Updated 4 years ago
- Tool to parse subdomains from dmarc.live☆153Apr 19, 2024Updated 2 years ago
- POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.☆128Jul 12, 2024Updated last year
- A streamlined tool for discovering private TLDs for security research.☆324Jun 8, 2026Updated last week
- ☆64Nov 30, 2024Updated last year
- 403/401 Bypass Methods + Bash Automation + Your Support ;)☆1,637Jun 6, 2022Updated 4 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- De-clutter a list of URLs☆390Mar 8, 2026Updated 3 months ago
- reverse engineered and improved BSQLi script from Coffinxp☆15Aug 30, 2024Updated last year
- ☆174Aug 9, 2025Updated 10 months ago
- SNMP Bash Script to discover valid community strings, dump basic information, check for write permission and check for RCE.☆11Apr 27, 2024Updated 2 years ago
- AssetViz simplifies the visualization of subdomains from input files, presenting them as a coherent mind map. Ideal for penetration test…☆38Feb 15, 2026Updated 4 months ago
- Fast and customizable subdomain wordlist generator using DSL☆968May 8, 2026Updated last month
- Parse FFUF results in GUI with option to sort based by response code , size , keyword☆101Sep 9, 2024Updated last year
- Subdomains wordlist generted from subdomains of public bug bounty programs☆11Mar 25, 2025Updated last year
- Android webviews and securiy☆25Sep 18, 2025Updated 8 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A modern tool written in Python that automates your xss findings.☆477Nov 26, 2023Updated 2 years ago
- Bug bounty domain manager with validation, exports & Redis storage ✨☆30Jun 5, 2025Updated last year
- a .js scanner, built in php. designed to scrape urls and other info☆229Aug 22, 2017Updated 8 years ago
- 「🔑」A tool used to hunt down API key leaks in JS files and pages☆909Mar 12, 2026Updated 3 months ago
- Crawlex is a powerful Chrome extension designed to assist bug bounty hunters in their work by enabling easy crawling of all possible URLs…☆12May 28, 2023Updated 3 years ago
- This is a python wrapper around the amazing KNOXSS API by Brute Logic☆286Mar 6, 2026Updated 3 months ago
- Zzl is a reconnaissance tool that collects subdomains from SSL certificates in IP ranges☆43Oct 27, 2024Updated last year