Meet wafrift: a programmable WAF-evasion engine. Product
Encoding and grammar mutation, HTTP smuggling, TLS fingerprint rotation, and an evolutionary loop that discovers what bypasses your exact WAF, then remembers it in a per-WAF gene bank. 2026-07-30 - evade, scan, detect, distill, and the verdict exit codes.
Meet gossan: attack-surface discovery in one scan. Product
Subdomains, ports, technology fingerprinting, hidden paths, cloud assets, and origin IP in one run. JSON you can diff, SARIF your Security tab already reads, and drop-in nmap XML. 2026-07-30 - one scan, every module, output your pipeline already reads.
Meet keyhog: a GPU-accelerated, open-source secret scanner. Product
Open-source secret scanner in Rust. SIMD on the CPU, an Aho-Corasick automaton on the GPU, live verification of which leaked keys are still active, and SARIF + JSON + TUI output. 2026-05-28 - What keyhog catches, how it stays accurate, and how to drop it into CI.