Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools: webapp (287)

Pentesting tools tagged webapp. See all tools or the category key.

Team (best effort)

0d1n

Web security tool to make fuzzing at HTTP inputs, made in C with libCurl.

webapp Red Team

abuse-ssl-bypass-waf

Bypassing WAF by abusing SSL/TLS Ciphers.

webapp Red Team

adfind

Simple admin panel finder for php,js,cgi,asp and aspx admin panels.

webapp Red Team

adminpagefinder

This python script looks for a large amount of possible administrative interfaces on a given site.

webapp Red Team

albatar

A SQLi exploitation framework in Python.

webapp Red Team

anti-xss

A XSS vulnerability scanner.

webapp Red Team

arachni

A feature-full, modular, high-performance Ruby framework aimed towards helping penetration testers and administrators ev

webapp Red Team

astra

Automated Security Testing For REST API's.

webapp Red Team

atlas

Open source tool that can suggest sqlmap tampers to bypass WAF/IDS/IPS.

webapp Red Team

badministration

A tool which interfaces with management or administration applications from an offensive standpoint.

webapp Red Team

badsecrets

A library for detecting known secrets across many web frameworks.

webapp Red Team

bbqsql

SQL injection exploit tool.

webapp Red Team

bbscan

A tiny Batch web vulnerability Scanner.

webapp Red Team

bing-lfi-rfi

Python script for searching Bing for sites that may have local and remote file inclusion vulnerabilities.

webapp Red Team

blisqy

Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

webapp Red Team

brutemap

Penetration testing tool that automates testing accounts to the site's login page.

webapp Red Team

brutexss

Cross-Site Scripting Bruteforcer.

webapp Red Team

bsqlbf

Blind SQL Injection Brute Forcer.

webapp Red Team

bsqlinjector

Blind SQL injection exploitation tool written in ruby.

webapp Red Team

c5scan

Vulnerability scanner and information gatherer for the Concrete5 CMS.

webapp Red Team

caido-desktop

Intercepting proxy to replay, inject, scan and fuzz HTTP requests.

webapp Red Team

cansina

A python-based Web Content Discovery Tool.

webapp Red Team

cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, token.

webapp Red Team

cent

Community edition nuclei templates.

webapp Red Team

chankro

Tool that generates a PHP capable of run a custom binary (like a meterpreter) or a bash script (p.e. reverse shell) bypa

webapp Red Team

cjexploiter

Drag and Drop ClickJacking exploit development assistance tool.

webapp Red Team

clairvoyance

Obtain GraphQL API Schema even if the introspection is not enabled.

webapp Red Team

cloudget

Python script to bypass cloudflare from command line. Built upon cfscrape module.

webapp Red Team

cms-few

Joomla, Mambo, PHP-Nuke, and XOOPS CMS SQL injection vulnerability scanning tool written in Python.

webapp Red Team

cmsfuzz

Fuzzer for wordpress, cold fusion, drupal, joomla, and phpnuke.

webapp Red Team

cmsscan

CMS scanner to identify and find vulnerabilities for Wordpress, Drupal, Joomla, vBulletin.

webapp Red Team

cmsscanner

CMS Scanner Framework.

webapp Red Team

comission

WhiteBox CMS analysis.

webapp Red Team

commentor

Extract all comments from the specified URL resource.

webapp Red Team

corscanner

Fast CORS misconfiguration vulnerabilities scanner.

webapp Red Team

corsy

CORS Misconfiguration Scanner.

webapp Red Team

crabstick

Automatic remote/local file inclusion vulnerability analysis and exploit tool.

webapp Red Team

crackql

GraphQL password brute-force and fuzzing utility

webapp Red Team

crawlic

Web recon tool (find temporary files, parse robots.txt, search folders, google dorks and search domains hosted on same s

webapp Red Team

csrftester

The OWASP CSRFTester Project attempts to give developers the ability to test their applications for CSRF flaws.

webapp Red Team

cybercrowl

A Python Web path scanner tool.

webapp Red Team

dalfox

Powerful open-source XSS scanner and utility focused on automation.

webapp Red Team

darkdump

Open Source Intelligence interface for Deep Web scraping.

webapp Red Team

darkjumper

This tool will try to find every website that host at the same server at your target.

webapp Red Team

darkscrape

OSINT Tool For Scraping Dark Websites.

webapp Red Team

davscan

Fingerprints servers, finds exploits, scans WebDAV.

webapp Red Team

dawnscanner

A static analysis security scanner for ruby written web applications.

webapp Red Team

dff-scanner

Tool for finding path of predictable resource locations.

webapp Red Team

dirble

Fast directory scanning and scraping tool.

webapp Red Team

dirbuster-ng

C CLI implementation of the Java dirbuster tool.

webapp Red Team

dirhunt

Find web directories without bruteforce.

webapp Red Team

dirscraper

OSINT Scanning tool which discovers and maps directories found in javascript files hosted on a website.

webapp Red Team

docem

Uility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids).

webapp Red Team

domi-owned

A tool used for compromising IBM/Lotus Domino servers.

webapp Red Team

dontgo403

Tool to bypass 40X response codes..

webapp Red Team

doork

Passive Vulnerability Auditor.

webapp Red Team

dorknet

Selenium powered Python script to automate searching for vulnerable web apps.

webapp Red Team

droopescan

A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstr

webapp Red Team

drupal-module-enum

Enumerate on drupal modules.

webapp Red Team

drupalscan

Simple non-intrusive Drupal scanner.

webapp Red Team

drupwn

Drupal enumeration & exploitation tool.

webapp Red Team

dsfs

A fully functional File inclusion vulnerability scanner (supporting GET and POST parameters) written in under 100 lines

webapp Red Team

dsjs

A fully functional JavaScript library vulnerability scanner written in under 100 lines of code.

webapp Red Team

dsss

A fully functional SQL injection vulnerability scanner (supporting GET and POST parameters) written in under 100 lines o

webapp Red Team

dsstore-crawler

A parser + crawler for .DS_Store files exposed publically.

webapp Red Team

dsxs

A fully functional Cross-site scripting vulnerability scanner (supporting GET and POST parameters) written in under 100

webapp Red Team

eos

Enemies Of Symfony - Debug mode Symfony looter.

webapp Red Team

epicwebhoneypot

Tool which aims to lure attackers using various types of web vulnerability scanners by tricking them into believing that

webapp Red Team

evine

Interactive CLI Web Crawler.

webapp Red Team

extended-ssrf-search

Smart ssrf scanner using different methods like parameter brute forcing in post and get.

webapp Red Team

fbht

A Facebook Hacking Tool

webapp Red Team

fdsploit

A File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

webapp Red Team

fhttp

This is a framework for HTTP related attacks. It is written in Perl with a GTK interface, has a proxy for debugging and

webapp Red Team

filebuster

An extremely fast and flexible web fuzzer.

webapp Red Team

filegps

A tool that help you to guess how your shell was renamed after the server-side script of the file uploader saved it.

webapp Red Team

fimap

A little tool for local and remote file inclusion auditing and exploitation.

webapp Red Team

fingerprinter

CMS/LMS/Library etc Versions Fingerprinter.

webapp Red Team

flask-session-cookie-manager2

Decode and encode Flask session cookie.

webapp Red Team

flask-session-cookie-manager3

Decode and encode Flask session cookie.

webapp Red Team

fockcache

Tool to make cache poisoning by trying X-Forwarded-Host and X-Forwarded-Scheme headers on web pages.

webapp Red Team

fuxploider

Tool that automates the process of detecting and exploiting file upload forms flaws.

webapp Red Team

gau

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

webapp Red Team

ghauri

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws.

webapp Red Team

ghost-py

Webkit based webclient (relies on PyQT).

webapp Red Team

gitdump

A pentesting tool that dumps the source code from .git even when the directory traversal is disabled.

webapp Red Team

gittools

A repository with 3 tools for pwn'ing websites with .git repositories available'.

webapp Red Team

golismero

Opensource web security testing framework.

webapp Red Team

goop-dump

Tool to dump a git repository from a website, focused on as-complete-as-possible dumps and handling weird edge-cases.

webapp Red Team

gopherus

Tool generates gopher link for exploiting SSRF and gaining RCE in various servers.

webapp Red Team

grabber

A web application scanner. Basically it detects some kind of vulnerabilities in your website.

webapp Red Team

graphql-path-enum

Tool that lists the different ways of reaching a given type in a GraphQL schema.

webapp Red Team

graphqlmap

Scripting engine to interact with a graphql endpoint for pentesting purposes.

webapp Red Team

graphw00f

GraphQL endpoint detection and engine fingerprinting.

webapp Red Team

grpc-pentest-suite

Set of tools for pentesting gRPC-Web Applications.

webapp Red Team

h2csmuggler

HTTP Request Smuggling over HTTP/2 Cleartext (h2c).

webapp Red Team

h2t

Scans a website and suggests security headers to apply.

webapp Red Team

hetty

HTTP toolkit for security research. Aims to become an open source alternative to commercial software like Burp Suite Pro

webapp Red Team

hookshot

Integrated web scraper and email account data breach comparison tool.

webapp Red Team

htcap

A web application analysis tool for detecting communications between javascript and the server.

webapp Red Team

http2smugl

Http2Smugl - Tool to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -> HTTP/1.1 conver

webapp Red Team

httpforge

A set of shell tools that let you manipulate, send, receive, and analyze HTTP messages. These tools can be used to test,

webapp Red Team

httpgrep

Async HTTP(S) scanner that greps response bodies and headers for strings or regex across hosts, ports, CIDR/ranges and T

webapp Red Team

httppwnly

"Repeater" style XSS post-exploitation tool for mass browser control.

webapp Red Team

httpx

A fast and multi-purpose HTTP toolkit allow to run multiple probers using retryablehttp library.

webapp Red Team

identywaf

Blind WAF identification tool.

webapp Red Team

injectus

CRLF and open redirect fuzzer.

webapp Red Team

interactsh-client

Open-Source Solution for Out of band Data Extraction.

webapp Red Team

ipsourcebypass

This Python script can be used to bypass IP source restrictions using HTTP headers.

webapp Red Team

jaeles

The Swiss Army knife for automated Web Application Testing.

webapp Red Team

jaidam

Penetration testing tool that would take as input a list of domain names, scan them, determine if wordpress or joomla pl

webapp Red Team

jast

Just Another Screenshot Tool.

webapp Red Team

jdeserialize

A library that interprets Java serialized objects. It also comes with a command-line tool that can generate compilable c

webapp Red Team

jexboss

Jboss verify and Exploitation Tool.

webapp Red Team

jira-scan

A simple remote scanner for Atlassian Jira

webapp Red Team

jok3r

Network and Web Pentest Framework.

webapp Red Team

jomplug

This php script fingerprints a given Joomla system and then uses Packet Storm's archive to check for bugs related to the

webapp Red Team

jooforce

A Joomla password brute force tester.

webapp Red Team

joomlascan

Joomla scanner scans for known vulnerable remote file inclusion paths and files.

webapp Red Team

joomlavs

A black box, Ruby powered, Joomla vulnerability scanner.

webapp Red Team

jshell

Get a JavaScript shell with XSS.

webapp Red Team

jsonbee

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP).

webapp Red Team

jsparser

Parse javascript using Tornado and JSBeautifier to discover interesting enpoints.

webapp Red Team

jsql-injection

A Java application for automatic SQL database injection.

webapp Red Team

jstillery

Advanced JavaScript Deobfuscation via Partial Evaluation.

webapp Red Team

juumla

Python tool created to identify Joomla version, scan for vulnerabilities and search for config files.

webapp Red Team

jwt-hack

A tool for hacking / security testing to JWT.

webapp Red Team

kadimus

LFI Scan & Exploit Tool.

webapp Red Team

katana-pd

Crawling and spidering framework.

webapp Red Team

kiterunner

Contextual Content Discovery Tool.

webapp Red Team

konan

Advanced Web Application Dir Scanner.

webapp Red Team

kubolt

Utility for scanning public kubernetes clusters.

webapp Red Team

lfi-exploiter

This perl script leverages /proc/self/environ to attempt getting code execution out of a local file inclusion vulnerabil

webapp Red Team

lfi-fuzzploit

A simple tool to help in the fuzzing for, finding, and exploiting of local file inclusion vulnerabilities in Linux-based

webapp Red Team

lfi-image-helper

A simple script to infect images with PHP Backdoors for local file inclusion attacks.

webapp Red Team

lfi-sploiter

This tool helps you exploit LFI (Local File Inclusion) vulnerabilities. Post discovery, simply pass the affected URL and

webapp Red Team

lfifreak

A unique automated LFi Exploiter with Bind/Reverse Shells.

webapp Red Team

lfimap

Local file inclusion discovery and exploitation tool.

webapp Red Team

liffy

A Local File Inclusion Exploitation tool.

webapp Red Team

lightbulb

Python framework for auditing web applications firewalls.

webapp Red Team

linkfinder

Discovers endpoint and their parameters in JavaScript files.

webapp Red Team

list-urls

Extracts links from webpage.

webapp Red Team

log4j-bypass

Log4j web app tester that includes WAF bypasses.

webapp Red Team

log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-44228.

webapp Red Team

lorsrf

Find the parameters that can be used to find SSRF or Out-of-band resource load.

webapp Red Team

lulzbuster

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl.

webapp Red Team

magescan

Scan a Magento site for information.

webapp Red Team

malicious-pdf

Generate a bunch of malicious pdf files with phone-home functionality.

webapp Red Team

mando.me

Web Command Injection Tool.

webapp Red Team

meg

Fetch many paths for many hosts - without killing the hosts.

webapp Red Team

metoscan

Tool for scanning the HTTP methods supported by a webserver.

webapp Red Team

monsoon

A fast HTTP enumerator that allows you to execute a large number of HTTP requests.

webapp Red Team

mooscan

A scanner for Moodle LMS.

webapp Red Team

morxtraversal

Path Traversal checking tool.

webapp Red Team

multiinjector

Automatic SQL injection utility using a lsit of URI addresses to test parameter manipulation.

webapp Red Team

nosqli

NoSQL scanner and injector.

webapp Red Team

nosqlmap

Automated Mongo database and NoSQL web application exploitation tool

webapp Red Team

novahot

A webshell framework for penetration testers.

webapp Red Team

okadminfinder

Tool to find admin panels / admin login pages.

webapp Red Team

onionsearch

Script that scrapes urls on different .onion search engines.

webapp Red Team

opendoor

OWASP WEB Directory Scanner.

webapp Red Team

owasp-bywaf

A web application penetration testing framework (WAPTF).

webapp Red Team

owtf

The Offensive (Web) Testing Framework.

webapp Red Team

pappy-proxy

An intercepting proxy for web application testing.

webapp Red Team

parameth

This tool can be used to brute discover GET and POST parameters.

webapp Red Team

parampampam

This tool for brute discover GET and POST parameters.

webapp Red Team

paramspider

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing.

webapp Red Team

payloadmask

Web Payload list editor to use techniques to try bypass web application firewall.

webapp Red Team

peepingtom

A tool to take screenshots of websites. Much like eyewitness.

webapp Red Team

phantomcollect

Lightweight stealth web data collection framework for ethical security testing.

webapp Red Team

php-findsock-shell

A Findsock Shell implementation in PHP + C.

webapp Red Team

php-malware-finder

Detect potentially malicious PHP files.

webapp Red Team

pinkerton

JavaScript file crawler and secret finder.

webapp Red Team

pixload

Image Payload Creating/Injecting tools.

webapp Red Team

plecost

Wordpress finger printer Tool.

webapp Red Team

plown

A security scanner for Plone CMS.

webapp Red Team

poly

Polymorphic webshells.

webapp Red Team

pown

Security testing and exploitation toolkit built on top of Node.js and NPM.

webapp Red Team

ppfuzz

A fast tool to scan client-side prototype pollution vulnerability written in Rust.

webapp Red Team

ppmap

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known ga

webapp Red Team

proxenet

THE REAL hacker friendly proxy for web application pentests.

webapp Red Team

pwndrop

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

webapp Red Team

pyfiscan

Free web-application vulnerability and version scanner.

webapp Red Team

python-witnessme

Web Inventory tool, takes screenshots of webpages using Pyppeteer.

webapp Red Team

python2-jsbeautifier

JavaScript unobfuscator and beautifier.

webapp Red Team

rabid

A CLI tool and library allowing to simply decode all kind of BigIP cookies.

webapp Red Team

rapidscan

The Multi-Tool Web Vulnerability Scanner.

webapp Red Team

recollapse

Tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications.

webapp Red Team

remot3d

An Simple Exploit for PHP Language.

webapp Red Team

restler-fuzzer

First stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding securi

webapp Red Team

riwifshell

Web backdoor - infector - explorer.

webapp Red Team

rookie

Load cookies from your web browsers.

webapp Red Team

ruler

A tool to abuse Exchange services.

webapp Red Team

rustbuster

DirBuster for Rust.

webapp Red Team

rww-attack

Performs a dictionary attack against a live Microsoft Windows Small Business Server.

webapp Red Team

sawef

Send Attack Web Forms.

webapp Red Team

scanqli

SQLi scanner to detect SQL vulns.

webapp Red Team

scrying

Collect RDP, web, and VNC screenshots smartly.

webapp Red Team

second-order

Second-order subdomain takeover scanner.

webapp Red Team

secretfinder

A python script to find sensitive data (apikeys, accesstoken, jwt,..) in javascript files.

webapp Red Team

secscan

Web Apps Scanner and Much more utilities.

webapp Red Team

see-surf

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

webapp Red Team

serializationdumper

A tool to dump Java serialization streams in a more human readable form.

webapp Red Team

shortfuzzy

A web fuzzing script written in perl.

webapp Red Team

shuffledns

A wrapper around massdns written in GO.

webapp Red Team

sitadel

Web Application Security Scanner.

webapp Red Team

sitediff

Fingerprint a web app using local files as the fingerprint sources.

webapp Red Team

sj

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

webapp Red Team

smplshllctrlr

PHP Command Injection exploitation tool.

webapp Red Team

smuggler

An HTTP Request Smuggling / Desync testing tool written in Python 3.

webapp Red Team

smuggler-py

Python tool used to test for HTTP Desync/Request Smuggling attacks.

webapp Red Team

snallygaster

Tool to scan for secret files on HTTP servers.

webapp Red Team

snuck

Automatic XSS filter bypass.

webapp Red Team

sourcemapper

Extract JavaScript source trees from Sourcemap files.

webapp Red Team

spaf

Static Php Analysis and Fuzzer.

webapp Red Team

sparty

An open source tool written in python to audit web applications using sharepoint and frontpage architecture.

webapp Red Team

spiga

Configurable web resource scanner.

webapp Red Team

spike-proxy

A Proxy for detecting vulnerabilities in web applications

webapp Red Team

spipscan

SPIP (CMS) scanner for penetration testing purpose written in Python.

webapp Red Team

sqid

A SQL injection digger.

webapp Red Team

ssrf-sheriff

A simple SSRF-testing sheriff written in Go.

webapp Red Team

ssrfmap

Automatic SSRF fuzzer and exploitation tool.

webapp Red Team

stews

A Security Tool for Enumerating WebSockets.

webapp Red Team

striker

An offensive information and vulnerability scanner.

webapp Red Team

subjs

Fetches javascript file from a list of URLS or subdomains.

webapp Red Team

themole

Automatic SQL injection exploitation tool.

webapp Red Team

tidos-framework

Offensive Web Application Penetration Testing Framework.

webapp Red Team

torcrawl

Crawl and extract (regular or onion) webpages through TOR network.

webapp Red Team

tplmap

Automatic Server-Side Template Injection Detection and Exploitation Tool.

webapp Red Team

typo3scan

Enumerate Typo3 version and extensions.

webapp Red Team

uncaptcha2

Defeating the latest version of ReCaptcha with 91% accuracy.

webapp Red Team

uppwn

A script that automates detection of security flaws on websites' file upload systems'.

webapp Red Team

urldigger

A python tool to extract URL addresses from different HOT sources and/or detect SPAM and malicious code

webapp Red Team

urlextractor

Information gathering & website reconnaissance.

webapp Red Team

urx

Extracts URLs from OSINT Archives for Security Insights.

webapp Red Team

vane

A vulnerability scanner which checks the security of WordPress installations using a black box approach.

webapp Red Team

vanguard

A comprehensive web penetration testing tool written in Perl thatidentifies vulnerabilities in web applications.

webapp Red Team

vbscan

A black box vBulletin vulnerability scanner written in perl.

webapp Red Team

vsvbp

Black box tool for Vulnerability detection in web applications.

webapp Red Team

vulnerabilities-spider

A tool to scan for web vulnerabilities.

webapp Red Team

vulnx

Cms and vulnerabilites detector & An intelligent bot auto shell injector.

webapp Red Team

w13scan

Passive Security Scanner.

webapp Red Team

wafninja

A tool which contains two functions to attack Web Application Firewalls.

webapp Red Team

wafp

An easy to use Web Application Finger Printing tool written in ruby using sqlite3 databases for storing the fingerprints

webapp Red Team

wafpass

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

webapp Red Team

wascan

Web Application Scanner.

webapp Red Team

waybackpack

Download the entire Wayback Machine archive for a given URL.

webapp Red Team

wayparam

Fetch and normalize parameterized URLs from the Wayback CDX API.

webapp Red Team

wcvs

Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning.

webapp Red Team

web-soul

A plugin based scanner for attacking and data mining web sites written in Perl.

webapp Red Team

webanalyze

Port of Wappalyzer (uncovers technologies used on websites) in go to automate scanning.

webapp Red Team

webborer

A directory-enumeration tool written in Go.

webapp Red Team

webhandler

A handler for PHP system functions & also an alternative 'netcat' handler.

webapp Red Team

webkiller

Tool Information Gathering Write By Python.

webapp Red Team

webslayer

A tool designed for brute forcing Web Applications.

webapp Red Team

webtech

Identify technologies used on websites.

webapp Red Team

webxploiter

An OWASP Top 10 Security scanner.

webapp Red Team

weirdaal

AWS Attack Library.

webapp Red Team

whatwaf

Detect and bypass web application firewalls and protection systems.

webapp Red Team

whichcdn

Tool to detect if a given website is protected by a Content Delivery Network.

webapp Red Team

witchxtool

A perl script that consists of a port scanner, LFI scanner, MD5 bruteforcer, dork SQL injection scanner, fresh proxy sca

webapp Red Team

wordpress-exploit-framework

A Ruby framework for developing and using modules which aid in the penetration testing of WordPress powered websites and

webapp Red Team

wpforce

Wordpress Attack Suite.

webapp Red Team

wpintel

Chrome extension designed for WordPress Vulnerability Scanning and information gathering.

webapp Red Team

wpseku

Simple Wordpress Security Scanner.

webapp Red Team

ws-attacker

A modular framework for web services penetration testing.

webapp Red Team

wssip

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.

webapp Red Team

wuzz

Interactive cli tool for HTTP inspection.

webapp Red Team

x8

Hidden parameters discovery suite.

webapp Red Team

xmlrpc-bruteforcer

An XMLRPC brute forcer targeting Wordpress written in Python 3.

webapp Red Team

xspear

Powerful XSS Scanning and Parameter analysis tool&gem.

webapp Red Team

xss-freak

An XSS scanner fully written in Python3 from scratch.

webapp Red Team

xsscon

Simple XSS Scanner tool.

webapp Red Team

xsscrapy

XSS spider - 66/66 wavsep XSS detected.

webapp Red Team

xssless

An automated XSS payload generator written in python.

webapp Red Team

xsspy

Web Application XSS Scanner.

webapp Red Team

xsss

A brute force cross site scripting scanner.

webapp Red Team

xssscan

Command line tool for detection of XSS attacks in URLs. Based on ModSecurity rules from OWASP CRS.

webapp Red Team

xsssniper

An automatic XSS discovery tool

webapp Red Team

xssya

A Cross Site Scripting Scanner & Vulnerability Confirmation.

webapp Red Team

xwaf

Automatic WAF bypass tool.

webapp Red Team

xxxpwn

A tool Designed for blind optimized XPath 1 injection attacks.

webapp Red Team

xxxpwn-smart

A fork of xxxpwn adding further optimizations and tweaks.

webapp Red Team

yaaf

Yet Another Admin Finder.

webapp Red Team

yasuo

A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network.

webapp Red Team

yawast

The YAWAST Antecedent Web Application Security Toolkit.

webapp Red Team

ycrawler

A web crawler that is useful for grabbing all user supplied input related to a given website and will save the output. I

webapp Red Team

ysoserial

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

webapp Red Team