πΈοΈ Web Application Security
This category hosts scanning, directory brute-forcing, JavaScript analysis, and parameter parsing tools to evaluate vulnerabilities in web environments.
Tool Catalog
Select a tool below to view detailed specifications, cheatsheets, or definitions.
Nuclei
Highly customizable template-based YAML vulnerability scanner by ProjectDiscovery.
Nikto
Classic Perl scanner to probe configuration settings and files on web servers.
ffuf
Ultra-fast web fuzzer in Go designed to brute-force URLs, paths, and headers.
Gobuster
Multi-threaded directory, file, VHost, and DNS brute-forcer.
Arjun
Heuristic HTTP parameter discovery suite mapping hidden endpoints inputs.
x8
Rust-based parameter and custom header discovery utility.
WhatWeb / Wappalyzer / Webanalyze
Offensive application technology profile fingerprinting engines identifying CMS, JS frameworks, and headers.
CMSeeK / WPScan
Vulnerability scanners specialized in content management frameworks (WordPress, Joomla, Drupal).
Feroxbuster / Dirsearch / wfuzz
Advanced directory scanners and web application input fuzzer engines.
ParamSpider
Mining URL parameter structures from archive indexes like Wayback.
LinkFinder / JSFinder / SecretFinder
JavaScript static analysis scripts to harvest endpoints, API urls, and hardcoded API tokens.
Trufflehog / Gitleaks
Entropy scanners searching git repository history for leaked passwords and certificates.
Waybackurls / Gau / Katana
URL scanners and history index aggregators to collect all endpoints belonging to the target.