andresriancho / w3af
w3af: web application attack and audit framework, the open source web vulnerability scanner.
☆4,665Updated last year
Alternatives and similar repositories for w3af:
Users that are interested in w3af are comparing it to the libraries listed below
- Web Application Security Scanner Framework☆3,837Updated last year
- Nikto web server scanner☆8,915Updated 2 weeks ago
- Web application fuzzer☆6,050Updated 5 months ago
- Automated All-in-One OS Command Injection Exploitation Tool.☆4,723Updated this week
- WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.☆5,504Updated last month
- Next generation web scanner☆5,713Updated 6 months ago
- Open Source Vulnerability Management Platform☆5,188Updated 2 weeks ago
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.☆8,384Updated last year
- Advanced vulnerability scanning with Nmap NSE☆3,548Updated 5 months ago
- Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.☆3,641Updated 2 weeks ago
- Weaponized web shell☆3,243Updated 3 months ago
- Attack Surface Management Platform☆8,403Updated last month
- The legacy Exploit Database repository - New repo located at https://gitlab.com/exploit-database/exploitdb☆7,752Updated 2 years ago
- Automated NoSQL database enumeration and web application exploitation tool.☆3,005Updated 6 months ago
- Git All the Payloads! A collection of web attack payloads.☆3,676Updated last year
- ZMap is a fast single packet network scanner designed for Internet-wide network surveys.☆5,633Updated this week
- A Tool for Domain Flyovers☆5,710Updated 2 years ago
- NSE script based on Vulners.com API☆3,267Updated 10 months ago
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and…☆3,738Updated 3 years ago
- Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run yo…☆3,618Updated this week
- WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websit…☆8,795Updated this week
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆3,864Updated 9 months ago
- The ZAP by Checkmarx Core project☆13,049Updated this week
- A DNS meta-query spider that enumerates DNS records, and subdomains.☆3,393Updated 3 years ago
- A swiss army knife for pentesting networks☆8,570Updated last year
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,153Updated 3 months ago
- DNS Enumeration Script☆2,709Updated this week
- The Browser Exploitation Framework Project☆10,036Updated this week
- The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.☆5,225Updated 4 months ago
- ✍️ A curated list of CVE PoCs.☆3,367Updated 3 years ago