awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

15 Repos

Awesome GitHub RepositoriesWeb Application Firewalls

Gateways that monitor and filter incoming web traffic to block malicious requests targeting specific applications.

Explore 15 awesome GitHub repositories matching security & cryptography · Web Application Firewalls. Refine with filters or upvote what's useful.

Awesome Web Application Firewalls GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • awesome-selfhosted/awesome-selfhostedAvatar von awesome-selfhosted

    awesome-selfhosted/awesome-selfhosted

    299,516Auf GitHub ansehen↗

    Dieses Projekt ist ein von der Community kuratiertes Verzeichnis von Open-Source-Software, die für den Einsatz in privaten Serverumgebungen und Home-Labs konzipiert ist. Es dient als umfassende Ressource zur Entdeckung unabhängiger, selbst gehosteter Alternativen zu gängigen Cloud-Diensten und ermöglicht es Nutzern, die volle Datenhoheit und Kontrolle über ihre digitale Infrastruktur zu behalten. Das Verzeichnis ist durch eine hierarchische Taxonomie strukturiert, die eine riesige Sammlung von Anwendungen in logische Kategorien organisiert, von Medienmanagement und Datenanalyse bis hin zu privater Kommunikation und Tools für die Teamproduktivität. Es zeichnet sich durch einen kollaborativen Peer-Review-Prozess aus, bei dem Community-Mitglieder die Qualität und Relevanz jeder Einreichung validieren, um sicherzustellen, dass das Verzeichnis korrekt und zuverlässig bleibt. Das Projekt deckt ein breites Spektrum an Fähigkeiten ab, einschließlich Infrastruktur-Automatisierung, containerbasierter Service-Bereitstellung und deklarativem Konfigurationsmanagement. Diese Tools unterstützen Nutzer bei der Aufrechterhaltung reproduzierbarer Serverumgebungen und der Verwaltung komplexer Service-Abhängigkeiten auf privater Hardware. Das Verzeichnis wird als versionskontrolliertes Repository gepflegt, wodurch sichergestellt wird, dass alle Updates und Community-gesteuerten Änderungen nachverfolgt und transparent sind.

    Filters incoming web traffic to block malicious requests and prevent unauthorized access by scraper bots.

    awesomeawesome-listcloud
    Auf GitHub ansehen↗299,516
  • traefik/traefikAvatar von traefik

    traefik/traefik

    63,644Auf GitHub ansehen↗

    Traefik is a cloud-native edge router and API gateway designed to manage service communication and traffic flow across distributed infrastructure. It functions as a dynamic service proxy that automatically discovers backend services and configures routing rules in real time, eliminating the need for manual restarts or complex configuration updates. By integrating directly with container orchestrators and service registries, it maintains a consistent state for network traffic, load balancing, and security policy enforcement. The project distinguishes itself through its deep integration with di

    Embeds high-performance firewall capabilities directly into the traffic path to secure API endpoints without external dependencies.

    Goconsuldockeretcd
    Auf GitHub ansehen↗63,644
  • chaitin/safelineAvatar von chaitin

    chaitin/SafeLine

    21,527Auf GitHub ansehen↗

    SafeLine is a containerized web application firewall and reverse proxy designed to secure web services by inspecting incoming HTTP traffic. It acts as a security gateway that sits in front of backend infrastructure to filter malicious requests and enforce access policies before they reach the application server. The platform distinguishes itself through advanced bot mitigation and content protection capabilities. It employs challenge-response mechanisms to verify human users and dynamically obfuscates HTML and JavaScript content to prevent unauthorized scraping and code tampering. These featu

    Inspects incoming HTTP traffic to block common web vulnerabilities and malicious requests as a reverse proxy firewall.

    Goapi-gatewayapplication-securityappsec
    Auf GitHub ansehen↗21,527
  • qax-os/excelizeAvatar von qax-os

    qax-os/excelize

    20,682Auf GitHub ansehen↗

    Excelize is a library for reading and writing spreadsheet files in the Office Open XML format. It provides a comprehensive suite of tools for programmatically creating, modifying, and analyzing workbooks, worksheets, and cell data, ensuring compatibility across various office software suites through structured XML serialization. The library distinguishes itself with a built-in formula calculation engine that evaluates complex mathematical and logical expressions directly against workbook data. It also features a memory-mapped streaming architecture, which allows for the efficient processing o

    Inspects incoming traffic against a rule engine to detect and block common web exploits like SQL injection.

    Goagentaianalytics
    Auf GitHub ansehen↗20,682
  • ultimatehackers/xsstrikeAvatar von UltimateHackers

    UltimateHackers/XSStrike

    15,027Auf GitHub ansehen↗

    XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.

    Identifies the presence of security filters and applies specific evasion techniques to bypass them.

    Python
    Auf GitHub ansehen↗15,027
  • aws/aws-cdkAvatar von aws

    aws/aws-cdk

    12,817Auf GitHub ansehen↗

    The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It

    Integrates with web application firewalls to filter malicious traffic and defend against common web-based attacks.

    TypeScriptawscloud-infrastructurehacktoberfest
    Auf GitHub ansehen↗12,817
  • crowdsecurity/crowdsecAvatar von crowdsecurity

    crowdsecurity/crowdsec

    12,574Auf GitHub ansehen↗

    CrowdSec is a collaborative, distributed security engine designed for threat detection and infrastructure protection. It functions as an intrusion detection system that parses logs and network traffic to identify malicious patterns, utilizing a bucket-based threshold detection model to aggregate events and trigger alerts. The platform is built on a modular architecture that includes a centralized local API server for managing security signals and a relational database for persistent storage of remediation decisions. What distinguishes the project is its decoupled enforcement model, which offl

    Configures web application firewall rules to inspect and filter incoming traffic for malicious patterns.

    Goattacks-preventiondetectionids
    Auf GitHub ansehen↗12,574
  • bunkerity/bunkerized-nginxAvatar von bunkerity

    bunkerity/bunkerized-nginx

    10,629Auf GitHub ansehen↗

    Bunkerized Nginx is a containerized security automation system that provides a secure reverse proxy and web application firewall. It focuses on protecting web applications by monitoring container labels within cloud-native orchestration systems to automatically update security settings and firewall rules. The system distinguishes itself through automated security operations, including the automatic management of SSL certificates and an automated client banning mechanism that blocks IP addresses based on HTTP status codes. It features bot challenge mechanisms using CAPTCHAs, JavaScript, or coo

    Provides a gateway to monitor and filter incoming web traffic to protect applications from common cyber attacks.

    Python
    Auf GitHub ansehen↗10,629
  • fuzzdb-project/fuzzdbAvatar von fuzzdb-project

    fuzzdb-project/fuzzdb

    8,819Auf GitHub ansehen↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    Provides curated lists of patterns and regex dictionaries to bypass security filters and WAFs during testing.

    PHP
    Auf GitHub ansehen↗8,819
  • six2dez/reconftwAvatar von six2dez

    six2dez/reconftw

    7,226Auf GitHub ansehen↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Includes utilities designed to identify the presence and type of web application firewalls protecting a target.

    Shellbug-bountybugbountybugbounty-tool
    Auf GitHub ansehen↗7,226
  • daffainfo/allaboutbugbountyAvatar von daffainfo

    daffainfo/AllAboutBugBounty

    6,644Auf GitHub ansehen↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    Provides WAF-specific payloads to deliver cross-site scripting attacks by evading security filters.

    bugbugbountybugbountytips
    Auf GitHub ansehen↗6,644
  • enablesecurity/wafw00fAvatar von EnableSecurity

    EnableSecurity/wafw00f

    6,414Auf GitHub ansehen↗

    WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

    Identifies whether a website is protected by a WAF through HTTP response analysis.

    Python
    Auf GitHub ansehen↗6,414
  • amidaware/tacticalrmmAvatar von amidaware

    amidaware/tacticalrmm

    4,161Auf GitHub ansehen↗

    TacticalRMM is a remote monitoring and management platform designed for overseeing endpoints and automating IT administration. It functions as an endpoint management tool and IT automation framework, providing a centralized dashboard for executing scripts, monitoring system health, and managing remote devices across multiple tenants. The platform distinguishes itself through a comprehensive remote administration suite that includes real-time shell access, remote file management, and registry editing. It integrates with third-party remote desktop software and provides a hierarchical policy inh

    Implements a core rule set to detect and block common web attacks while allowing legitimate traffic.

    Pythondjangodjango-rest-frameworkmonitoring
    Auf GitHub ansehen↗4,161
  • allinssl/allinsslAvatar von allinssl

    allinssl/allinssl

    3,359Auf GitHub ansehen↗

    Allinssl is a multi-platform certificate manager and ACME automator designed to handle the full lifecycle of security certificates. It provides a web-based management interface to orchestrate the issuance, renewal, and deployment of certificates across various servers and cloud environments. The system distinguishes itself through an orchestration engine that pushes certificates to diverse targets, including web application firewalls, server control panels, and remote hosts. It automates domain ownership verification using DNS challenges across multiple providers and employs an event-driven w

    Automates the delivery of SSL certificates to Safeline WAF using API tokens.

    TypeScriptacmeautomationgo
    Auf GitHub ansehen↗3,359
  • jcmoraisjr/haproxy-ingressAvatar von jcmoraisjr

    jcmoraisjr/haproxy-ingress

    1,160Auf GitHub ansehen↗

    This project is a Kubernetes ingress controller that manages external traffic by dynamically configuring the HAProxy load balancer. It functions as a bridge between cluster resources and the network data plane, translating high-level ingress definitions into active proxy configurations to route HTTP, TCP, and UDP traffic into containerized environments. The controller distinguishes itself through a decoupled architecture that separates control plane logic from the proxy process, allowing for independent lifecycle management and versioning. It utilizes template-based configuration generation a

    Connects to external security agents to inspect incoming traffic for malicious patterns and block unauthorized requests.

    Gohacktoberfesthaproxyingress-controller
    Auf GitHub ansehen↗1,160
  1. Home
  2. Security & Cryptography
  3. Network and Infrastructure Security
  4. Web and Network Security
  5. Web Application Firewalls

Unter-Tags erkunden

  • Firewall Detection Tools1 Sub-TagUtilities designed to identify the presence and type of web application firewalls protecting a target. **Distinct from Web Application Firewalls:** Focuses on the identification (fingerprinting) of the firewall rather than just the bypassing of it.
  • Native API SecurityHigh-performance firewall integration within the gateway.
  • WAF Bypass Payloads2 Sub-TagsCurated patterns and dictionaries designed to evade Web Application Firewall filters. **Distinct from Web Application Firewalls:** Focuses on the bypass payloads rather than the WAF infrastructure itself.
  • WAF Event AnalysisMonitoring and analysis of blocked attack patterns and security logs within a web application firewall. **Distinct from Web Application Firewalls:** Focuses on the analysis and tracking of attack patterns specifically from the WAF perspective.
  • WAF Plugin DeploymentsModular security components that integrate firewall rules into existing application delivery pipelines.