Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools: webapps (8)

Pentesting tools tagged webapps. See all tools or the category key.

Team (best effort)

commix-git

Find and exploit a command injection vulnerability in a certain vulnerable parameter or string.

webapps Red Team

powerupsql-git

Powershell Toolkit for Attacking SQL Server

webapps Red Team

see-surf-git

A Python based scanner to find potential SSRF parameters in a web application.

webapps Red Team

vega

An open source platform to test the security of web applications

webapps Red Team

whatweb-git

Next generation web scanner that identifies what websites are running.

webapps Red Team

wig-git

WebApp Information Gatherer

webapps Red Team

xssf

A Cross-Site Scripting Framework for metasploit

webapps Red Team

xssscan-git

Command line tool for detection of XSS attacks in URLs. Based on ModSecurity rules from OWASP CRS.

webapps Red Team