Skip to content

Entry

OWASP ZAP

Appears in 4 awesome lists

World’s most popular free web security tools and is actively maintained by a dedicated international team of volunteers

Open github.comzaproxy/zaproxy

Found in these lists

Awesome Bug Bounty Tools

Section: Vulnerability Scanners · World’s most popular free web security tools and is actively maintained by a dedicated international team of volunteers

FreshScore 89

Awesome Devsecops

Section: Dynamic Analysis · OWASP - An open-source web application vulnerability scanner, including an API for CI/CD integration.

StaleScore 52

Awesome Termux Hacking

Section: General · The OWASP ZAP core project.

StaleScore 47

Awesome Testing

Section: Security Testing · Intercepting proxy for HTTP traffic manipulation, security scanning, and exploitation.

FreshScore 86

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more..

In 14 listsDetails

sqlmap

Tamper scripts in SQLMap obfuscate payloads which might evade some WAFs.

In 10 listsDetails

mitmproxy

An interactive HTTPS proxy that allows inspection, modification, and debugging of network traffic, useful for video streaming analysis.

In 10 listsDetails

nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud…

In 8 listsDetails

Volatility

Python based memory extraction and analysis framework.

In 8 listsDetails

gobuster

Lean multipurpose brute force search/fuzzing tool for Web (and DNS) reconnaissance.

In 7 listsDetails

Metasploit

A tool for developing and executing exploit code against a remote target machine. Other important sub-projects include the Opcode Database, shellcode archive and related research.

In 7 listsDetails

Sublist3r

Sublist3r is a multi-threaded sub-domain enumeration tool for penetration testers by @aboul3la.

In 7 listsDetails