- Burp Suite - Framework.
- ZAP Proxy - Framework.
- Metasploit - Framework.
- FFUF - HTTP probing.
- WFUZZ - HTTP probing.
- autossrf - HTTP probing.
- HTTPX - HTTP probing.
- httpie - HTTP probing.
- jless - JSON viewer.
- Dirsearch - HTTP bruteforcing.
- Nmap - Port scanning.
- Sublist3r - Subdomain discovery.
- Amass - Subdomain discovery.
- Lazy Recon - Subdomain discovery.
- SQLmap - SQLi exploitation.
- WPscan - WordPress exploitation.
- Nikto - Webserver scanning.
- Nuclei - YAML based template scanning.
- Subfinder - Subdomain discovery.
- Masscan - Mass IP and port scanner.
- XSS Hunter - Blind XSS discovery.
- Aquatone - HTTP based recon.
- LinkFinder - Endpoint discovery through JS files.
- JS-Scan - Endpoint discovery through JS files.
- GAU - Historical attack surface mapping.
- Parameth - Bruteforce GET and POST parameters.
- truffleHog - Find credentials in GitHub commits.
- git-secrets - Find credentials in GitHub commits.