evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).
-
Updated
Aug 7, 2026 - Python
evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).
针对GPT 5.6的破甲实验项目,基于Rust开发
Simulation, Training and Red Team Phishing Framework
Local proxy that compresses your LLM API requests so you pay less, with no change to the answers. Trims wasted tokens from prompts, history, tool output, and code before they're sent: -31% input / -74% output, measured live. Any provider, no extra model calls. Also an MCP server and embeddable library (Rust, Python, Ruby, Kotlin, Swift, JS/TS).
MITM HTTP debugging proxy: HTTPS, MongoDB, Redis, MySQL and gRPC. Also makes JSON logs human readable.
OS Cert Auth - provides info on managing CA certs on various operating systems
The collaborative web app pentest suite
TLS fingerprint emulation upstream proxy replay any ClientHello
AI-Powered Offensive Security Research Engine - desktop-native security testing platform with native MCP integration. 90 tools, MITM proxy, stealth browser, autonomous AI agent. Built on Tauri + Rust + React.
Defense-in-depth security toolkit for LLM agents — taint tracking, proxy secret guard, policy engine, and red-team benchmarking
Free, self-hosted alternative to Burp Suite Pro — MITM proxy + full active scanner (SQLi/XSS/SSRF/XXE/SSTI/smuggling), recon→CVE, OAST, nuclei-style templates, and a CI security gate. Qt6/C++, MIT, no telemetry.
A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML config file.
Enterprise AI traffic gateway — unified compliance, routing across 20+ LLM providers, semantic cache, quotas, and audit. SDK / network / OS-layer intercept.
AI-native MITM proxy — MCP server for traffic interception, recording & replay
MITM proxy for Claude Code with real-time TUI, web UI & MCP server — intercept, inspect, and send messages to the Anthropic API. Headless mode for automation.
Real-time LLM token and cost monitor with TLS-intercepting proxy or HTTP relay; cross-platform with macOS status bar app and browser dashboard
抓包 · HTTPS 证书 · 协议逆向 · AI 分析· JA3。 AI-native desktop traffic capture, protocol analysis, AI evidence reports, request replay, and code generation.
Windows fork of pxpipe: transparent Fable 5 compression for Claude Desktop on Windows 11.
See exactly what your coding agent does on the wire. TLS-intercepting tracer for the Claude Code, Codex, Grok and Kimi CLIs: full first-party capture in a live web UI — reconstructed sessions, session replay, find-in-session, per-turn cost/cache/latency, and a cross-project dashboard of every run.
Keep your secrets out of your AI coding agents. A local HTTPS proxy that swaps real credentials with placeholders and injects them at the network boundary.
To associate your repository with the mitm-proxy topic, visit your repo's landing page and select "manage topics."