πŸ•ΈοΈ Web Application Security

This category hosts scanning, directory brute-forcing, JavaScript analysis, and parameter parsing tools to evaluate vulnerabilities in web environments.

Tool Catalog

Select a tool below to view detailed specifications, cheatsheets, or definitions.

🎯

Nuclei

Highly customizable template-based YAML vulnerability scanner by ProjectDiscovery.

View Wiki β†’
πŸ’½

Nikto

Classic Perl scanner to probe configuration settings and files on web servers.

View Wiki β†’
⚑

ffuf

Ultra-fast web fuzzer in Go designed to brute-force URLs, paths, and headers.

View Wiki β†’
πŸ“‚

Gobuster

Multi-threaded directory, file, VHost, and DNS brute-forcer.

View Wiki β†’
πŸ”‘

Arjun

Heuristic HTTP parameter discovery suite mapping hidden endpoints inputs.

View Wiki β†’
πŸš€

x8

Rust-based parameter and custom header discovery utility.

View Wiki β†’
🏷️

WhatWeb / Wappalyzer / Webanalyze

Offensive application technology profile fingerprinting engines identifying CMS, JS frameworks, and headers.

πŸ›‘οΈ

CMSeeK / WPScan

Vulnerability scanners specialized in content management frameworks (WordPress, Joomla, Drupal).

πŸ“‚

Feroxbuster / Dirsearch / wfuzz

Advanced directory scanners and web application input fuzzer engines.

πŸ•·οΈ

ParamSpider

Mining URL parameter structures from archive indexes like Wayback.

πŸ“œ

LinkFinder / JSFinder / SecretFinder

JavaScript static analysis scripts to harvest endpoints, API urls, and hardcoded API tokens.

πŸ—ƒοΈ

Trufflehog / Gitleaks

Entropy scanners searching git repository history for leaked passwords and certificates.

πŸ”—

Waybackurls / Gau / Katana

URL scanners and history index aggregators to collect all endpoints belonging to the target.


πŸ”— Back to Toolkit