Web reconnaissance, exploitation techniques, and HTTP utility commands for authorized testing.
8 categories · 83 commands

Web application reconnaissance and enumeration commands for discovering directories, subdomains, and web technologies.

Common web application exploitation techniques and test payloads for authorized penetration testing.

Useful web utilities for downloading files, making HTTP requests, and inspecting domain and network information.

Fast web fuzzer written in Go. Fuzz directories, subdomains, virtual hosts, parameters, and POST data with high performance and flexible filtering.

Fast passive subdomain discovery tool using multiple public sources including APIs, certificate transparency logs, and DNS datasets.

Directory, file, DNS, VHost, S3 bucket, and TFTP bruteforce tool written in Go. Fast and flexible enumeration for web targets.

Web technology fingerprinting tool. Identifies CMS, blogging platforms, JavaScript libraries, web servers, analytics packages, and more.

Next-generation web crawling and spidering framework by ProjectDiscovery. Crawls both standard and JavaScript-heavy applications with scope control.