Web Scanning
22 tools indexed
Web application scanning tools for directory brute-forcing, technology fingerprinting, vulnerability detection, and crawling. These scanners probe web applications for common misconfigurations, exposed files, known CVEs, and injection points that could lead to compromise.
httpx
Fast multi-purpose HTTP toolkit. Probes for running HTTP servers with retries and fallbacks.
Nikto
Classic web server scanner. Tests for dangerous files, outdated server software, and version-specific problems.
Gobuster
Directory/file, DNS, and vhost busting tool. Brute-forces URIs, DNS subdomains, virtual host names, and S3 buckets.
Feroxbuster
Fast, recursive content discovery tool written in Rust. Like gobuster on steroids with auto-recursion.
Burp Suite Community
Web vulnerability scanner and proxy. Intercept, modify, and replay HTTP/S traffic for web app testing.
ffuf
Fast web fuzzer written in Go. Fuzz anything — URLs, headers, POST data — with blazing speed.
Katana
Next-gen crawling and spidering framework. Headless browser and standard mode with automatic form fill.
waybackurls
Fetch all URLs that the Wayback Machine knows about for a domain. Gold mine for hidden endpoints.
gau
Get All URLs. Fetches known URLs from AlienVault OTX, Wayback Machine, Common Crawl, and URLScan.
Arjun
HTTP parameter discovery suite. Finds hidden query parameters in web applications using smart heuristics.
Wfuzz
Web application fuzzer. Brute force parameters, directories, headers, and authentication credentials.
WhatWeb
Web technology fingerprinter. Identifies CMS, frameworks, JS libraries, servers, and analytics from HTTP responses.
ParamSpider
Mine parameters from web archives for any domain to find hidden attack surfaces.
GoSpider
Fast web spider written in Go for crawling and collecting URLs, subdomains, and endpoints.
Hakrawler
Simple Go web crawler for quick discovery of endpoints and assets within a web application.
LinkFinder
Python script to discover endpoints and their parameters in JavaScript files.
SecretFinder
Discover sensitive data like API keys, tokens, and credentials in JavaScript files.
JSFScan
Automation framework combining multiple JS analysis tools for comprehensive JavaScript recon.
dirsearch
Mature web path discovery tool with recursive scanning, wordlist-based bruteforcing, and extensive extension support.
meg
Fetch many paths for many hosts concurrently without overloading servers — ideal for large-scale recon on bug bounties.
Caido
Lightweight and modern web security testing toolkit built in Rust, designed as a fast alternative to Burp Suite.
SilverBullet
Multi-purpose automation suite for web testing with configurable request sequences, scraping, and credential testing.