andresriancho / w3afView external linksLinks
w3af: web application attack and audit framework, the open source web vulnerability scanner.
☆4,853Feb 22, 2023Updated 2 years ago
Alternatives and similar repositories for w3af
Users that are interested in w3af are comparing it to the libraries listed below
Sorting:
- Web Application Security Scanner Framework☆3,996May 22, 2025Updated 8 months ago
- Nikto web server scanner☆10,065Feb 1, 2026Updated 2 weeks ago
- Web application fuzzer☆6,411Jan 21, 2026Updated 3 weeks ago
- Next generation web scanner☆6,406Oct 19, 2025Updated 3 months ago
- The ZAP by Checkmarx Core project☆14,751Updated this week
- Automatic SQL injection and database takeover tool☆36,602Feb 5, 2026Updated last week
- Open Source Vulnerability Management Platform☆6,255Jan 26, 2026Updated 2 weeks ago
- WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.☆6,157Jan 27, 2026Updated 2 weeks ago
- Attack Surface Management Platform☆9,386Jan 12, 2026Updated last month
- Web path scanner☆13,979Updated this week
- WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websit…☆9,448Feb 9, 2026Updated last week
- Most advanced XSS scanner.☆14,735Apr 26, 2025Updated 9 months ago
- Metasploit Framework☆37,499Updated this week
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.☆8,810Nov 10, 2023Updated 2 years ago
- Automated All-in-One OS Command Injection Exploitation Tool☆5,624Feb 8, 2026Updated last week
- The Browser Exploitation Framework Project☆10,718Feb 9, 2026Updated last week
- Automated NoSQL database enumeration and web application exploitation tool.☆3,230Aug 26, 2025Updated 5 months ago
- Fast subdomains enumeration tool for penetration testers☆10,802Aug 2, 2024Updated last year
- Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices☆12,044Updated this week
- A Tool for Domain Flyovers☆5,897May 22, 2022Updated 3 years ago
- A swiss army knife for pentesting networks☆9,056Dec 6, 2023Updated 2 years ago
- A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑☆8,818Oct 9, 2025Updated 4 months ago
- Empire is a PowerShell and Python post-exploitation agent.☆7,798Jan 19, 2020Updated 6 years ago
- Advanced vulnerability scanning with Nmap NSE☆3,717Feb 6, 2026Updated last week
- Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.o…☆1,926Jan 21, 2026Updated 3 weeks ago
- The legacy Exploit Database repository - New repo located at https://gitlab.com/exploit-database/exploitdb☆7,842Nov 10, 2022Updated 3 years ago
- TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.☆25,305Jun 5, 2025Updated 8 months ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,741Dec 4, 2025Updated 2 months ago
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,638Jan 5, 2026Updated last month
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,117Apr 21, 2024Updated last year
- Exploitation Framework for Embedded Devices☆12,968Jun 10, 2025Updated 8 months ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆12,865Aug 17, 2020Updated 5 years ago
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on th…☆4,169May 11, 2023Updated 2 years ago
- E-mails, subdomains and names Harvester - OSINT☆15,617Feb 8, 2026Updated last week
- This project has stopped to maintenance, please to https://github.com/knownsec/pocsuite3 project.☆1,821May 27, 2022Updated 3 years ago
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and…☆3,897Sep 27, 2021Updated 4 years ago
- A DNS meta-query spider that enumerates DNS records, and subdomains.☆3,501Jan 13, 2022Updated 4 years ago
- This is a webshell open source project☆10,683Dec 24, 2024Updated last year
- Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.☆3,845May 20, 2025Updated 8 months ago