#1Tools specifically designed to exploit common web application vulnerabilities (e.g., SQL injection, XSS).
Kitploit recommended

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A collection of awesome penetration testing resources, tools and other shiny things

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Automatic SQL injection and database takeover tool

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

fsociety Hacking Tools Pack – A Penetration Testing Framework

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Fast web fuzzer written in Go

Web path scanner

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

The Browser Exploitation Framework Project

A next-generation crawling and spidering framework.

autonomous red teaming platform; multi-agent offensive-security meta-harness

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…