Blind WAF identification tool
☆727Jun 25, 2024Updated last year
Alternatives and similar repositories for identYwaf
Users that are interested in identYwaf are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.☆6,316Apr 19, 2026Updated last week
- Detect and bypass web application firewalls and protection systems☆2,894Aug 11, 2024Updated last year
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,148Apr 21, 2024Updated 2 years ago
- Bypassing WAF by abusing SSL/TLS Ciphers☆321Jul 27, 2021Updated 4 years ago
- Automatic SSRF fuzzer and exploitation tool☆3,533Sep 4, 2025Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- OneForAll是一款功能强大的子域收集工具☆9,747Sep 12, 2025Updated 7 months ago
- Fast web fuzzer written in Go☆15,957Updated this week
- Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack…☆3,231May 24, 2024Updated last year
- 基于chrome、firefox插件的被动式信息泄漏检测工具☆1,401Nov 17, 2024Updated last year
- Quick SQLMap Tamper Suggester☆1,400Jul 18, 2022Updated 3 years ago
- HTTP parameter discovery suite.☆6,209Feb 20, 2025Updated last year
- HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.☆4,162Updated this week
- Unexpected information 是用于标记请求包中的一些敏感信息、JS接口和一些特殊字段的BurpSuite 插件。☆690Jan 4, 2021Updated 5 years ago
- JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.☆2,925Nov 24, 2021Updated 4 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- 一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN…☆3,523Dec 18, 2022Updated 3 years ago
- Next generation web scanner☆6,510Apr 2, 2026Updated 3 weeks ago
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the ac…☆1,795Apr 26, 2024Updated 2 years ago
- EHole(棱洞)3.0 重构版-红队重点攻击系统指纹探测工具☆3,467Apr 2, 2024Updated 2 years ago
- 一款完全被动监听的谷歌插件,用于高危指纹识别、蜜罐特征告警和拦截、机器特征对抗☆1,665Jan 19, 2023Updated 3 years ago
- Local file inclusion exploitation tool☆949Oct 1, 2025Updated 6 months ago
- Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥☆7,452Mar 26, 2026Updated last month
- This tool generates gopher link for exploiting SSRF and gaining RCE in various servers☆3,346Apr 18, 2023Updated 3 years ago
- 侦查守卫(ObserverWard)的指纹库☆1,362Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications…☆1,435Sep 17, 2024Updated last year
- CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs☆2,532Apr 9, 2024Updated 2 years ago
- Burp suite 分块传输辅助插件☆2,033Feb 23, 2022Updated 4 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,854Dec 4, 2025Updated 4 months ago
- A powerful browser crawler for web vulnerability scanners☆3,031Mar 11, 2025Updated last year
- Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.☆1,739Dec 1, 2024Updated last year
- Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner☆1,931Apr 13, 2022Updated 4 years ago
- Linux privilege escalation auditing tool☆6,470Mar 20, 2026Updated last month
- domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等☆2,123Apr 10, 2026Updated 2 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Most advanced XSS scanner.☆14,913Apr 26, 2025Updated last year
- Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点☆2,145Jan 29, 2024Updated 2 years ago
- A toolkit for testing, tweaking and cracking JSON Web Tokens☆6,515May 1, 2025Updated 11 months ago
- 红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool☆2,120Apr 21, 2026Updated last week
- Username guessing tool primarily for use against the default Solaris SMTP service. Can use either EXPN, VRFY or RCPT TO.☆156Apr 20, 2022Updated 4 years ago
- TideFinger——指纹识别小工具,汲取整合了多个web指纹库,结合了多种指纹检测方法,让指纹检测更快捷、准确。☆2,070May 23, 2023Updated 2 years ago
- pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.☆3,840Feb 28, 2025Updated last year