
WhatWeb
Next generation web scanner

Next generation web scanner

phpMyAdmin XSS

Stage two containers

Orchestration component of purpleteam

TLS checking component of purpleteam

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…