Web Scanning
41 tools indexed
Web application scanning tools for directory brute-forcing, technology fingerprinting, vulnerability detection, and crawling. These scanners probe web applications for common misconfigurations, exposed files, known CVEs, and injection points that could lead to compromise.
httpx
Fast multi-purpose HTTP toolkit. Probes for running HTTP servers with retries and fallbacks.
Nikto
Classic web server scanner. Tests for dangerous files, outdated server software, and version-specific problems.
Gobuster
Directory/file, DNS, and vhost busting tool. Brute-forces URIs, DNS subdomains, virtual host names, and S3 buckets.
Feroxbuster
Fast, recursive content discovery tool written in Rust. Like gobuster on steroids with auto-recursion.
Burp Suite Community
Web vulnerability scanner and proxy. Intercept, modify, and replay HTTP/S traffic for web app testing.
ffuf
Fast web fuzzer written in Go. Fuzz anything - URLs, headers, POST data - with blazing speed.
Katana
Next-gen crawling and spidering framework. Headless browser and standard mode with automatic form fill.
waybackurls
Fetch all URLs that the Wayback Machine knows about for a domain. Gold mine for hidden endpoints.
gau
Get All URLs. Fetches known URLs from AlienVault OTX, Wayback Machine, Common Crawl, and URLScan.
Arjun
HTTP parameter discovery suite. Finds hidden query parameters in web applications using smart heuristics.
Wfuzz
Web application fuzzer. Brute force parameters, directories, headers, and authentication credentials.
WhatWeb
Web technology fingerprinter. Identifies CMS, frameworks, JS libraries, servers, and analytics from HTTP responses.
ParamSpider
Mine parameters from web archives for any domain to find hidden attack surfaces.
GoSpider
Fast web spider written in Go for crawling and collecting URLs, subdomains, and endpoints.
Hakrawler
Simple Go web crawler for quick discovery of endpoints and assets within a web application.
LinkFinder
Python script to discover endpoints and their parameters in JavaScript files.
SecretFinder
Discover sensitive data like API keys, tokens, and credentials in JavaScript files.
JSFScan
Automation framework combining multiple JS analysis tools for comprehensive JavaScript recon.
dirsearch
Mature web path discovery tool with recursive scanning, wordlist-based bruteforcing, and extensive extension support.
meg
Fetch many paths for many hosts concurrently without overloading servers - ideal for large-scale recon on bug bounties.
Caido
Lightweight and modern web security testing toolkit built in Rust, designed as a fast alternative to Burp Suite.
SilverBullet
Multi-purpose automation suite for web testing with configurable request sequences, scraping, and credential testing.
Interactsh
Out-of-band interaction server. Detect blind vulnerabilities with DNS, HTTP, SMTP, and LDAP callback listeners.
Aquatone
Visual web discovery tool. Takes screenshots of web pages across large target lists and generates browsable HTML reports.
EyeWitness
Web screenshot and categorization tool. Captures screenshots of web pages, RDP, and VNC services with auto-categorization.
CRLFuzz
CRLF injection scanner. Fast detection of HTTP response splitting vulnerabilities across multiple URLs.
Smuggler
HTTP request smuggling tester. Detects CL.TE, TE.CL, and TE.TE desync vulnerabilities in web servers and proxies.
reNgine
Automated reconnaissance framework with correlated scan engines, continuous monitoring, and vulnerability reporting.
reconftw
Automated recon pipeline orchestrating subdomain enum, vulnerability scanning, and OSINT via best-of-breed tools.
wafw00f
Identify and fingerprint Web Application Firewall products protecting a site.
SSLyze
Fast TLS/SSL configuration analyzer for identifying misconfigurations.
Wapiti
Black-box web application vulnerability scanner with built-in fuzzer modules.
Bearer
SAST tool scanning code for security risks, sensitive data flows, and vulnerabilities.
Bandit
Python static analysis security linter to find common code vulnerabilities.
OWASP ZAP
Full-featured intercepting proxy for web application security testing. Automated scanners, fuzzing, scripting, and API testing built in.
Kiterunner
API-aware content discovery tool that brute-forces routes using contextual wordlists derived from real API schemas.
Tplmap
Automated server-side template injection detection and exploitation tool supporting 15+ template engines.
Brakeman
Static analysis security scanner for Ruby on Rails applications. Finds SQL injection, XSS, and dozens of Rails-specific vulnerabilities.
BunkerWeb
Open-source Web Application Firewall with built-in security hardening, bot detection, and DDoS protection.
Shannon
Autonomous AI pentester for web apps and APIs. Analyzes source code, identifies attack vectors, and executes real exploits to prove vulnerabilities.
Lonkero
Professional web app scanner with 126+ checks, ML-powered false positive reduction, proof-based XSS detection, and blind SQLi engine.