
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Open Source Vulnerability Management Platform

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

End to End testing of Web, API, Cloud, Events and Security

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

AI-powered offensive security testing using autonomous agents, directly in your terminal.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

⚡️ Multiple target ZAP Scanning