Product.
Announcements, releases, and the architecture behind the tools.
Meet wafrift: a programmable WAF-evasion engine.
Product
→
Encoding and grammar mutation, HTTP smuggling, TLS fingerprint rotation, and an evolutionary loop that discovers what bypasses your exact WAF, then remembers it in a per-WAF gene bank.
2026-07-30 - evade, scan, detect, distill, and the verdict exit codes.
Meet gossan: attack-surface discovery in one scan.
Product
→
Subdomains, ports, technology fingerprinting, hidden paths, cloud assets, and origin IP in one run. JSON you can diff, SARIF your Security tab already reads, and drop-in nmap XML.
2026-07-30 - one scan, every module, output your pipeline already reads.
Meet keyhog: a GPU-accelerated, open-source secret scanner.
Product
→
Open-source secret scanner in Rust. SIMD on the CPU, an Aho-Corasick automaton on the GPU, live verification of which leaked keys are still active, and SARIF + JSON + TUI output.
2026-05-28 - What keyhog catches, how it stays accurate, and how to drop it into CI.