A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Aug 3, 2025 - Python
Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Opiniated RAG for integrating GenAI in your apps 🧠 Focus on your product rather than the RAG. Easy integration in existing products with customisation! Any LLM: GPT4, Groq, Llama. Any Vectorstore: PGVector, Faiss. Any Files. Anyway you want.
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Set up a personal VPN in the cloud
🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.
The authentication glue you need.
Daemon to ban hosts that cause multiple authentication errors
The Rogue Access Point Framework
Web path scanner
Exploitation Framework for Embedded Devices
Prowler is the Open Cloud Security platform for AWS, Azure, GCP, Kubernetes, M365 and more. It helps for continuous monitoring, security assessments & audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, ENS and more
OpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.
Scapy: the Python-based interactive packet manipulation program & library.
Main Sigma Rule Repository
🛡️ Open-source and next-generation Web Application Firewall (WAF)
Low code web framework for real world applications, in Python and Javascript
Automatic, daily repo and metadata backup - no maintenance needed: fast restore, DR, AWS, and S3 cloud storage support
Protect your app from malicious open source dependencies
GuardRails provides continuous security feedback for modern development teams
We help developers write clean code
Find, fix (and prevent!) known vulnerabilities in your code
Code scanning at ludicrous speed. Find bugs and reachable dependency vulnerabilities. Enforce standards on every commit
Detect open source vulnerabilities in real time with suggested fixes for quick remediation
Runtime Code Review
Automated GitHub backups so you can recover fast, stay compliant, and never lose a line of code
Backup repositories, metadata and LFS into AWS, Azure, OneDrive, GCP. SOC2 Type II compliant. Pay per repositories, not seats
Dependency Automation service by Mend.io