Web Application
Content discovery, fuzzing, SQL injection and web exploitation. · 27 commands
Gobuster
mediumFast directory/DNS/vhost brute-forcer.
ffuf
mediumFuzz Faster U Fool — high-speed web fuzzer.
DIRB
mediumClassic recursive web content scanner.
feroxbuster
mediumFast, recursive content discovery in Rust.
Wfuzz
mediumWeb application fuzzer for content & parameters.
sqlmap
highAutomatic SQL injection detection & exploitation.
Commix
highAutomated command-injection exploitation.
Dalfox
highFast parameter-analysis XSS scanner.
XSSer
highAutomated framework to detect & exploit XSS.
JoomScan
highJoomla vulnerability/enumeration scanner.
CMSeeK
mediumDetect CMS and enumerate version/plugins.
Burp Suite
mediumThe industry-standard web proxy & testing suite.
OWASP ZAP
mediumFree, full-featured web app scanner & proxy.
dirsearch
mediumAdvanced web path brute-forcer.
Katana
mediumNext-gen crawling & spidering framework.
hakrawler
mediumFast web crawler for endpoint discovery.
Arjun
mediumHTTP parameter discovery tool.
ParamSpider
passiveMine parameters from web archives.
XSStrike
highAdvanced XSS detection with payload fuzzing.
jwt_tool
mediumTest and tamper JSON Web Tokens.
droopescan
highScanner for Drupal, SilverStripe & more.
gospider
mediumFast Go web spider.
gf (grep-friendly)
passivePattern wrapper to find interesting URLs.
qsreplace
passiveReplace query-string values in URLs.
anew
passiveAppend only new, unique lines to a file.
CRLFuzz
highScan for CRLF injection vulnerabilities.
Jaeles
highSignature-based web vulnerability scanner.