Unwaf is a Go tool designed to help identify WAF bypasses using passive techniques. It automates the process of discovering the real origin IP behind a WAF/CDN by combining multiple discovery methods and verifying candidates through HTML similarity comparison, SSL certificate fingerprinting, and HTTP header analysis.
☆184Feb 22, 2026Updated 5 months ago
Alternatives and similar repositories for unwaf
Users that are interested in unwaf are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- NetScan CLI is a command-line tool for retrieving and analyzing IP address information. It provides detailed subnet and organization data…☆62Sep 4, 2024Updated last year
- A simple bug bounty utility tool to remove uninteresting entries from a list of URLs.☆13Jul 22, 2024Updated 2 years ago
- AI-powered ffuf wrapper☆797Dec 4, 2025Updated 7 months ago
- JScripter is a Python script designed to scrape and save unique JavaScript files from a list of URLs or a single URL.☆30Jun 28, 2026Updated 3 weeks ago
- Tool to parse subdomains from dmarc.live☆154Apr 19, 2024Updated 2 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- this repo contains all nuclei templates for particular vulnerability that i used mosty while hunting..☆13Aug 15, 2024Updated last year
- Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration☆12Jun 2, 2024Updated 2 years ago
- SubOwner - A Simple tool check for subdomain takeovers.☆122Oct 18, 2024Updated last year
- SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty☆795Jun 21, 2026Updated last month
- CT Log Scanner☆567Dec 26, 2025Updated 7 months ago
- Scrape domain names from SSL certificates of arbitrary hosts☆693Mar 31, 2024Updated 2 years ago
- 403/401 Bypass Methods + Bash Automation + Your Support ;)☆1,655Jun 6, 2022Updated 4 years ago
- reverse engineered and improved BSQLi script from Coffinxp☆14Aug 30, 2024Updated last year
- Parse FFUF results in GUI with option to sort based by response code , size , keyword☆102Sep 9, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Firebase_Checker is Python tool to analyze APK files and web applications for Firebase-related vulnerabilities. This tool identifies secu…☆58Nov 6, 2025Updated 8 months ago
- ☆132Jul 15, 2021Updated 5 years ago
- how to look for Leaked Credentials !☆1,051May 6, 2024Updated 2 years ago
- A powerful asynchronous XSS scanner supporting up to 1,500 concurrent requests.☆172Aug 16, 2024Updated last year
- Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.☆28Feb 20, 2024Updated 2 years ago
- Will attempt to retrieve DB details for FastAdmin instances☆69Aug 20, 2024Updated last year
- POC for CVE-2024-40348. Will attempt to read /etc/passwd from target☆31Jul 21, 2024Updated 2 years ago
- Printer exploitation framework for penetration testing. Discovers printers via PJL scanning, checks for default credentials, and extracts…☆21Mar 10, 2026Updated 4 months ago
- 「🔑」A tool used to hunt down API key leaks in JS files and pages☆921Mar 12, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Zzl is a reconnaissance tool that collects subdomains from SSL certificates in IP ranges☆43Oct 27, 2024Updated last year
- A collection of DPAPI hunting and parsing BOFs☆38Mar 3, 2026Updated 4 months ago
- ☆121May 29, 2025Updated last year
- ☆64Nov 30, 2024Updated last year
- 🚀 XSSFUZZ - A tool for detecting XSS vulnerabilities in web applications.☆131Sep 13, 2024Updated last year
- This Chromium extension scans the page for external iFrames, Scripts, and Styles, logs them to the console, and checks if their domains a…☆68Jan 6, 2026Updated 6 months ago
- De-clutter a list of URLs☆391Mar 8, 2026Updated 4 months ago
- Useful scripts for tampermonkey that I used during bug hunting. Will be updated "au fil de l'eau"☆18Jun 2, 2025Updated last year
- ☆223Jun 11, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Use favicons to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.☆247Jul 10, 2026Updated 2 weeks ago
- Automated GitHub secret scanning with smart alerting & monitoring.☆31Jan 15, 2026Updated 6 months ago
- 🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast…☆1,820Jun 21, 2026Updated last month
- Fast and customizable subdomain wordlist generator using DSL☆982Jul 10, 2026Updated 2 weeks ago
- A powerful bash script for massive XSS scanning leveraging Brute Logic's KNOXSS API☆83Jan 24, 2025Updated last year
- ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities. It crawls a target website, extracts GET…☆60Feb 22, 2025Updated last year
- A modern tool written in Python that automates your xss findings.☆481Nov 26, 2023Updated 2 years ago